CVE-2024-4224: TP-Link Tl-SG1016DE

Medium severity, CVSS 5.4. EPSS: 0.3% chance of exploitation in the next 30 days.

An authenticated stored cross-site scripting (XSS) exists in the TP-Link TL-SG1016DE affecting version TL-SG1016DE(UN) V7.6_1.0.0 Build 20230616, which could allow an adversary to run JavaScript in an administrator's browser. This issue was fixed in TL-SG1016DE(UN) V7_1.0.1 Build 20240628.

Affected products

  • TP-Link Tl-SG1016DE: up to and including V7.6_1.0.0 Build 20230616; version 7.6_1.0.0build20230616 only

Published 2024-07-15. Last modified 2026-06-17.