### [CVE-2017-8078](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-8078) ![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brighgreen) ### Description On the TP-Link TL-SG108E 1.0, the upgrade process can be requested remotely without authentication (httpupg.cgi with a parameter called cmd). This affects the 1.1.2 Build 20141017 Rel.50749 firmware. ### POC #### Reference No PoCs from references. #### Github - https://github.com/geeklynad/TP-Link-ESCU