CVE-2017-8074: Critical severity TP-Link Tl-sg108e Firmware vulnerability
On the TP-Link TL-SG108E 1.0, a remote attacker could retrieve credentials from "SEND data" log lines where passwords are encoded in hexadecimal. This affects the 1.1.2 Build 20141017 Rel.50749 firmware.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-8074?
CVE-2017-8074 is considered to have a medium severity level due to the potential for remote attackers to gain access to sensitive credentials.
How do I fix CVE-2017-8074?
To fix CVE-2017-8074, you should upgrade the firmware of the TP-Link TL-SG108E to a version that addresses this vulnerability.
What devices are affected by CVE-2017-8074?
CVE-2017-8074 specifically affects the TP-Link TL-SG108E running firmware version 1.1.2 Build 20141017 Rel.50749.
What type of information can be exposed due to CVE-2017-8074?
CVE-2017-8074 allows remote attackers to retrieve plaintext credentials that are encoded in hexadecimal from the device logs.
Is there a workaround for CVE-2017-8074?
Currently, the most effective workaround for CVE-2017-8074 is to turn off remote management features on the device until a firmware update can be applied.