CVE-2025-0729 Details
Description
A vulnerability was found in TP-Link TL-SG108E 1.0.0 Build 20201208 Rel. 40304. It has been rated as problematic. This issue affects some unknown processing. The manipulation leads to clickjacking. The attack may be initiated remotely. Upgrading to version 1.0.0 Build 20250124 Rel. 54920(Beta) is able to address this issue. It is recommended to upgrade the affected component. The vendor was contacted early. They reacted very professional and provided a pre-fix version for their customers.
A clickjacking vulnerability has been identified in the TP-Link TL-SG108E switch, specifically in version 1.0.0 Build 20201208 Rel. 40304. This issue allows remote attackers to manipulate the user interface and trick users into performing actions they did not intend to.
Users can upgrade to version 1.0.0 Build 20250124 Rel. 54920(Beta) to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jan 27, 2025CISA-ADP
Assessed Jan 27, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/TheCyberDiver/Public-Disclosures-CVE-/blob/main/tp-link%20clickjacking.md | [email protected] | ExploitTechnical Description |
| https://static.tp-link.com/upload/beta/2025/202501/20250124/TL-SG108E(UN)%206.0_1.0.0%20Build%2020250124%20Rel.54920(Beta)_up.zip | [email protected] | Broken LinkVendor |
| https://vuldb.com/?ctiid.293507 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/?id.293507 | [email protected] | AdvisoryContent Wall |
| https://vuldb.com/?submit.478451 | [email protected] | Issue TrackingContent Wall |
| https://www.tp-link.com/ | [email protected] | Vendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-451 | User Interface (UI) Misrepresentation of Critical Information | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| TP-Link TL-SG108E | 1.0.0 Build 20201208 Rel. 40304 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 27, 2025 | New CVE Received | [email protected] |
Volerion