First published: Wed Dec 20 2017(Updated: )
Cross-site scripting (XSS) vulnerability in system_name_set.cgi in TP-Link TL-SG108E 1.0.0 allows authenticated remote attackers to submit arbitrary java script via the 'sysName' parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
TP-Link TL-SG108E Firmware | =1.0.0 | |
TP-Link TL-SG108E Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-17745 is categorized as a high severity vulnerability due to its potential for exploitation through cross-site scripting (XSS).
To mitigate CVE-2017-17745, update the TP-Link TL-SG108E firmware to the latest version that addresses this vulnerability.
CVE-2017-17745 affects users of TP-Link TL-SG108E with firmware version 1.0.0.
Exploitation of CVE-2017-17745 can lead to unauthorized execution of scripts in the user's browser, compromising user data.
Yes, CVE-2017-17745 allows authenticated remote attackers to exploit the vulnerability via the 'sysName' parameter.