CVE detail
CVE-2025-0730
A vulnerability classified as problematic has been found in TP-Link TL-SG108E 1.0.0 Build 20201208 Rel. 40304. Affected is an unknown function of the file /usr_account_set.cgi of the component HTTP GET Request Handler. The manipulation of the argument username/password leads to use of get request method with sensitive query strings. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. Upgrading to version 1.0.0 Build 20250124 Rel. 54920(Beta) is able to address this issue. It is recommended to upgrade the affected component. The vendor was contacted early. They reacted very professional and provided a pre-fix version for their customers.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 19.5 · diversity 16.5 · KEV 0.0 · OTX 0.0 · PoC 4.5
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
6 source links · newest first
- https://www.tp-link.com/www.tp-link.com
No excerpt available.
Vendor Advisorywww.tp-link.comJan 27, 2025, 5:15 PM - https://vuldb.com/?submit.478465vuldb.com
No excerpt available.
Exploitvuldb.comJan 27, 2025, 5:15 PM - https://vuldb.com/?id.293508vuldb.com
No excerpt available.
Exploitvuldb.comJan 27, 2025, 5:15 PM - https://vuldb.com/?ctiid.293508vuldb.com
No excerpt available.
Exploitvuldb.comJan 27, 2025, 5:15 PM - https://static.tp-link.com/upload/beta/2025/202501/20250124/TL-SG108E(UN)%206.0_1.0.0%20Build%2020250124%20Rel.54920(Beta)_up.zipstatic.tp-link.com
No excerpt available.
referencestatic.tp-link.comJan 27, 2025, 5:15 PM No excerpt available.
Exploitgithub.comJan 27, 2025, 5:15 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
1 repository references · best confidence 0.90 · max 0 stars
- TheCyberDiver/Public-Disclosures-CVE-High confidencegithubNVD Exploit reference0 starsDiscovered Jul 22, 2026, 12:20 PM
NVD labels the source link as Exploit; this is not independent verification of the repository's code.
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2017-17747CVSS 6.5 · Medium
Weak access controls in the Device Logout functionality on the TP-Link TL-SG108E v1.0.0 allow remote attackers to call the logout functionality, triggering a denial of service con…
- CVE-2017-17746CVSS 6.8 · Medium
Weak access control methods on the TP-Link TL-SG108E 1.0.0 allow any user on a NAT network with an authenticated administrator to access the device without entering user credentia…
- CVE-2017-17745CVSS 5.4 · Medium
Cross-site scripting (XSS) vulnerability in system_name_set.cgi in TP-Link TL-SG108E 1.0.0 allows authenticated remote attackers to submit arbitrary java script via the 'sysName'…
- CVE-2017-8078CVSS 5.3 · Medium
On the TP-Link TL-SG108E 1.0, the upgrade process can be requested remotely without authentication (httpupg.cgi with a parameter called cmd). This affects the 1.1.2 Build 20141017…
- CVE-2017-8077CVSS 7.5 · High
On the TP-Link TL-SG108E 1.0, there is a hard-coded ciphering key (a long string beginning with Ei2HNryt). This affects the 1.1.2 Build 20141017 Rel.50749 firmware.
- CVE-2017-8076CVSS 9.8 · Critical
On the TP-Link TL-SG108E 1.0, admin network communications are RC4 encoded, even though RC4 is deprecated. This affects the 1.1.2 Build 20141017 Rel.50749 firmware.