CVE-2026-34127 Details
Description
A stored cross-site scripting (XSS) vulnerability has been identified in the web management interface of TP-Link's TL-SG108PE v5 switch due to improper sanitation of the SYSNAM configuration parameter during configuration file import. An attacker with administrator access can inject malicious script into the device configuration, which may be stored and executed in the administrator’s browser when the affected interface is viewed. Successful exploitation may allow session cookie theft, unauthorized configuration changes, or access to sensitive information exposed through the management interface.
A stored cross-site scripting vulnerability has been identified in the web management interface of TP-Link's TL-SG108PE V5 switch. This vulnerability arises from improper sanitation of the SYSNAM configuration parameter during the import of configuration files. An attacker with administrator access can inject malicious scripts into the device's configuration, which may be executed in the administrator's browser when the affected interface is accessed. Exploitation of this vulnerability could lead to session cookie theft, unauthorized configuration changes, or access to sensitive information through the management interface.
Users are advised to update their devices to the latest firmware version 1.0.1 Build 20260330, available on the TP-Link official website.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 29, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.tp-link.com/en/support/download/tl-sg108pe/v5/#Firmware | TPLink | Product |
| https://www.tp-link.com/us/support/download/tl-sg108pe/v5/#Firmware | TPLink | Product |
| https://www.tp-link.com/us/support/faq/5110/ | TPLink | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | TPLink |
Affected Products
| Product | Versions |
|---|---|
| tp-link tl-sg108pe firmware | 1.0.1 |
CPE
Remediation
| |
| tp-link tl-sg108pe | 5.0 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 22, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | TPLink |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 1, 2026 | Initial Analysis | [email protected] |
| May 29, 2026 | New CVE Received | TPLink |