Remote Authentication Bypass in TP-Link Network Switch
CVE-2017-8078
5.3MEDIUM
What is CVE-2017-8078?
The TP-Link TL-SG108E 1.0 network switch is vulnerable due to a remote authentication bypass issue, allowing attackers to initiate the firmware upgrade process without requiring authentication. This flaw occurs through the 'httpupg.cgi' endpoint with a command parameter, exposing the device to potential unauthorized firmware modifications. Users are advised to restrict access to the affected device and apply the latest firmware updates to mitigate this vulnerability.