vendor:
TP-SG105E
by:
PCEumel
7.5
CVSS
HIGH
Unauthenticated Remote Reboot
284
CWE
Product Name: TP-SG105E
Affected Version From: 1.0.0
Affected Version To: 1.0.0
Patch Exists: YES
Related CWE: CVE-2019-16893
CPE: h:tp-link:tp-sg105e:1.0.0
Platforms Tested:
2020
TP-Link TP-SG105E 1.0.0 – Unauthenticated Remote Reboot
The TP-Link TP-SG105E is a "5-Port Gigabit Easy Smart Switch". It features a web front end and an application (Easy Smart Configuration Utility) for easy configuration management. The device does not properly restrict access to an internal API. It is therefore possible to remotely reboot the device by sending a HTTP POST request.
Mitigation:
Apply the patch provided by the vendor