Vulnerabilities > TP Link > TL Sg108E Firmware > 1.0.0

DATE CVE VULNERABILITY TITLE RISK
2017-12-20 CVE-2017-17747 Missing Authentication for Critical Function vulnerability in Tp-Link Tl-Sg108E Firmware 1.0.0
Weak access controls in the Device Logout functionality on the TP-Link TL-SG108E v1.0.0 allow remote attackers to call the logout functionality, triggering a denial of service condition.
low complexity
tp-link CWE-306
6.5
2017-12-20 CVE-2017-17746 Missing Authentication for Critical Function vulnerability in Tp-Link Tl-Sg108E Firmware 1.0.0
Weak access control methods on the TP-Link TL-SG108E 1.0.0 allow any user on a NAT network with an authenticated administrator to access the device without entering user credentials.
low complexity
tp-link CWE-306
6.8
2017-12-20 CVE-2017-17745 Cross-site Scripting vulnerability in Tp-Link Tl-Sg108E Firmware 1.0.0
Cross-site scripting (XSS) vulnerability in system_name_set.cgi in TP-Link TL-SG108E 1.0.0 allows authenticated remote attackers to submit arbitrary java script via the 'sysName' parameter.
network
low complexity
tp-link CWE-79
5.4