Junglewise Threat Intelligence

CVE-2026-34127: TP-Link TL-SG108PE stored XSS via configuration file import

CVE-2026-34127 · Severity: info · CVSS 5.3 · Published 2026-05-29

Vendors: TP-Link.

Executive brief

A security vulnerability exists in the TP-Link TL-SG108PE v5 network switch, a device used to connect and power hardware in small-to-medium business networks. An attacker with administrative access can upload a malicious configuration file that executes unauthorized code in the browser of any user managing the device. This could lead to the theft of login credentials, unauthorized changes to network settings, or the exposure of sensitive management data.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in the web management interface of the TP-Link TL-SG108PE v5 switch. The root cause is improper sanitation of the 'SYSNAM' configuration parameter when a configuration file is imported. An attacker with high privileges (administrator access) can craft a configuration file containing malicious JavaScript; when this file is imported and the management interface is subsequently viewed, the script executes in the context of the user's browser session. This can result in session cookie theft or unauthorized configuration modifications. The vulnerability is fixed in firmware version 1.0.1 Build 260330.

Affected products

  • TP-Link TL-SG108PE v5 (specifically v5.6) prior to firmware 1.0.1 Build 260330

Timeline

  • 2026-05-29: disclosed
  • 2026-05-29: advisory
  • 2026-03-30: patched: Firmware build date for the fix

References