CVE-2025-30237
The affected TP-Link Aginet devices contain a flaw in the web management interface where authentication checks are not consistently enforced on certain endpoints. An attacker can send specially crafted requests to bypass authentication and directly invoke privileged functionality without valid credentials. This issue arises from improper enforcement of access control mechanisms on sensitive operations. Successful exploitation may allow an unauthenticated attacker to execute privileged operations and gain full control of the device.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.7
- CVSS vector
- CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 0.22%
- CWE
- CWE-862
- Published
- 2026-08-10
- Last modified
- 2026-08-11
Affected products
- TP-Link Systems Inc. HB810(US2) V1.0/1.6/2.0/2.6
- TP-Link Systems Inc. HB810(EU1) V2.0
- TP-Link Systems Inc. HB710(US2) V1.6/1.0
- TP-Link Systems Inc. HB710(EU1) 1.0
- TP-Link Systems Inc. HB610(US2) V2.6/2.0
- TP-Link Systems Inc. HB610(EU1)
- TP-Link Systems Inc. HB610(CA) V2.0
- TP-Link Systems Inc. HB410( EU1) 1.0
Weakness type
Related vulnerabilities
- CVE-2026-8821 — Playbooks run owner channel membership permission bypass
- CVE-2026-20324 — Cisco Secure Firewall Management Center sftunnel Root Arbitrary Code Exectution Vulnerability
- CVE-2026-57139 — PraisonAI MCPServer exposes unauthenticated HTTP tools/call
- CVE-2026-75030 — Apache Syncope: Incomplete authorization checks for Group members deprovisioning
- CVE-2026-57131 — praisonai: Jobs API exposes agent-execution endpoints with no authentication
- CVE-2026-14349 — TrueBooker <= 1.2.3 - Missing Authorization to Unauthenticated Arbitrary User Email Modification via 'admin_addcustomer' AJAX Action
- CVE-2026-66887 — Missing Authorization in Digital Watchdog VMAX DVR and NVR Product Lineups
- CVE-2026-38056 — ST Engineering iDirect iQ-Series Terminals Missing Authorization