CVE-2026-34127

4.8 MEDIUM
Published: May 29, 2026 Modified: June 01, 2026
View on NVD

Description

A stored cross-site scripting (XSS) vulnerability has been identified in the web management interface of TP-Link's TL-SG108PE v5 switch due to improper sanitation of the SYSNAM configuration parameter during configuration file import. An attacker with administrator access can inject malicious script into the device configuration, which may be stored and executed in the administrator’s browser when the affected interface is viewed.     Successful exploitation may allow session cookie theft, unauthorized configuration changes, or access to sensitive information exposed through the management interface.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

CVSS v3.x Details

0.0 Low Medium High Critical 10.0
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
https://www.tp-link.com/en/support/download/tl-sg108pe/v5/#Firmware
Source: f23511db-6c3e-4e32-a477-6aa17d310630
Product
https://www.tp-link.com/us/support/download/tl-sg108pe/v5/#Firmware
Source: f23511db-6c3e-4e32-a477-6aa17d310630
Product
https://www.tp-link.com/us/support/faq/5110/
Source: f23511db-6c3e-4e32-a477-6aa17d310630
Vendor Advisory

3 reference(s) from NVD

Quick Stats

CVSS v3 Score
4.8 / 10.0
EPSS (Exploit Probability)
0.2%
15th percentile
Exploitation Status
Not in CISA KEV

Weaknesses (CWE)

Affected Vendors

tp-link