// For flags

CVE-2017-17747

TP-Link TL-SG108E XSS / Weak Access Control

Severity Score

6.5
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Weak access controls in the Device Logout functionality on the TP-Link TL-SG108E v1.0.0 allow remote attackers to call the logout functionality, triggering a denial of service condition.

Controles de acceso débiles en la funcionalidad de cierre de sesión del dispositivo en TP-Link TL-SG108E v1.0.0 permiten a los atacantes remotos llamar a la funcionalidad de cierre de sesión, desencadenando una condición de denegación de servicio.

TP-Link TL-SG108E with firmware 1.0.0 Build 20160722 Rel.50167 suffers from cross site scripting and weak access control vulnerabilities.

*Credits: N/A
CVSS Scores
Attack Vector
Adjacent
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Attack Vector
Adjacent
Attack Complexity
Low
Authentication
Single
Confidentiality
None
Integrity
None
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2017-12-18 CVE Reserved
  • 2017-12-20 CVE Published
  • 2024-05-06 EPSS Updated
  • 2024-08-05 CVE Updated
  • 2024-08-05 First Exploit
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-306: Missing Authentication for Critical Function
CAPEC
References (1)
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Tp-link
Search vendor "Tp-link"
Tl-sg108e Firmware
Search vendor "Tp-link" for product "Tl-sg108e Firmware"
1.0.0
Search vendor "Tp-link" for product "Tl-sg108e Firmware" and version "1.0.0"
-
Affected
in Tp-link
Search vendor "Tp-link"
Tl-sg108e
Search vendor "Tp-link" for product "Tl-sg108e"
1.0
Search vendor "Tp-link" for product "Tl-sg108e" and version "1.0"
-
Safe
Tp-link
Search vendor "Tp-link"
Tl-sg108e Firmware
Search vendor "Tp-link" for product "Tl-sg108e Firmware"
1.0.0
Search vendor "Tp-link" for product "Tl-sg108e Firmware" and version "1.0.0"
-
Affected
in Tp-link
Search vendor "Tp-link"
Tl-sg108e
Search vendor "Tp-link" for product "Tl-sg108e"
2.0
Search vendor "Tp-link" for product "Tl-sg108e" and version "2.0"
-
Safe
Tp-link
Search vendor "Tp-link"
Tl-sg108e Firmware
Search vendor "Tp-link" for product "Tl-sg108e Firmware"
1.0.0
Search vendor "Tp-link" for product "Tl-sg108e Firmware" and version "1.0.0"
-
Affected
in Tp-link
Search vendor "Tp-link"
Tl-sg108e
Search vendor "Tp-link" for product "Tl-sg108e"
3.0
Search vendor "Tp-link" for product "Tl-sg108e" and version "3.0"
-
Safe