CVE Explorer
CVE-2026-34127
A stored
cross-site scripting (XSS) vulnerability has been identified in the web
management interface of TP-Link's TL-SG108PE v5 switch due to improper sanitation of the SYSNAM
configuration parameter during configuration file import. An attacker with
administrator access can inject malicious script into the device configuration,
which may be stored and executed in the administrator’s browser when the
affected interface is viewed.
Successful
exploitation may allow session cookie theft,
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","product":"TL-SG108PE v5","vendor":"TP-Link Systems Inc.","versions":[{"lessThan":"1.0.1 Build 260330","status":"affected","version":"0","versionType":"custom"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:3be0569cdb9f1fb0e9c23ac57a5d321b03b20af8e036a425ebd41c67c9be751d · sha256:d944681e37dc53d9… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"ADJACENT","baseScore":5.3,"baseSeverity":"MEDIUM","exploitMaturity":"NOT_DEFINED","privilegesRequired":"HIGH","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"LOW","subConfidentialityImpact":"LOW","subIntegrityImpact":"NONE","userInteraction":"PASSIVE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:P/VC:H/VI:L/VA:H/SC:L/SI:N/SA:L","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnConfidentialityImpac…
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:3be0569cdb9f1fb0e9c23ac57a5d321b03b20af8e036a425ebd41c67c9be751d · sha256:d944681e37dc53d9… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-79","description":"CWE-79 Improper neutralization of input during web page generation ('cross-site scripting')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:3be0569cdb9f1fb0e9c23ac57a5d321b03b20af8e036a425ebd41c67c9be751d · sha256:d944681e37dc53d9… · /containers/cna/problemTypes/0/descriptions/0
Source references
3 source assertions{"tags":["patch"],"url":"https://www.tp-link.com/en/support/download/tl-sg108pe/v5/#Firmware"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:3be0569cdb9f1fb0e9c23ac57a5d321b03b20af8e036a425ebd41c67c9be751d · sha256:d944681e37dc53d9… · /containers/cna/references/0
{"tags":["patch"],"url":"https://www.tp-link.com/us/support/download/tl-sg108pe/v5/#Firmware"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:3be0569cdb9f1fb0e9c23ac57a5d321b03b20af8e036a425ebd41c67c9be751d · sha256:d944681e37dc53d9… · /containers/cna/references/1
{"tags":["vendor-advisory"],"url":"https://www.tp-link.com/us/support/faq/5110/"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:3be0569cdb9f1fb0e9c23ac57a5d321b03b20af8e036a425ebd41c67c9be751d · sha256:d944681e37dc53d9… · /containers/cna/references/2
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.