CVE-2025-0729
MEDIUMTP-Link TL-SG108E <1.0.0 Build 20201208 Rel. 40304 - Clickjacking
Title source: llmDescription
A vulnerability was found in TP-Link TL-SG108E 1.0.0 Build 20201208 Rel. 40304. It has been rated as problematic. This issue affects some unknown processing. The manipulation leads to clickjacking. The attack may be initiated remotely. Upgrading to version 1.0.0 Build 20250124 Rel. 54920(Beta) is able to address this issue. It is recommended to upgrade the affected component. The vendor was contacted early. They reacted very professional and provided a pre-fix version for their customers.
References (6)
Core 6
Core References
Permissions Required, VDB Entry vdb-entry
https://vuldb.com/?id.293507
Permissions Required, VDB Entry signature
permissions-required
https://vuldb.com/?ctiid.293507
Permissions Required, VDB Entry third-party-advisory
https://vuldb.com/?submit.478451
Various Sources related
https://github.com/TheCyberDiver/Public-Disclosures-CVE-/blob/main/tp-link%20clickjacking.md
Various Sources patch
https://static.tp-link.com/upload/beta/2025/202501/20250124/TL-SG108E(UN)%206.0_1.0.0%20Build%2020250124%20Rel.54920(Beta)_up.zip
Various Sources product
https://www.tp-link.com/
Scores
CVSS v3
4.3
EPSS
0.0040
EPSS Percentile
31.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-451
Status
published
Products (1)
TP-Link/TL-SG108E
1.0.0 Build 20201208 Rel. 40304
Published
Jan 27, 2025
Tracked Since
Feb 18, 2026