CVE-2025-30238
In affected TP-Link Aginet devices, insufficient authorization validation allows authenticated low-privileged users to execute higher-privileged operations. An attacker may perform administrative actions such as creating privileged accounts or modifying critical configuration settings.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.6
- CVSS vector
- CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 0.14%
- CWE
- CWE-863
- Published
- 2026-08-10
- Last modified
- 2026-08-11
Affected products
- TP-Link Systems Inc. HB810(US2) V1.0/1.6/2.0/2.6
- TP-Link Systems Inc. HB810(EU1) V2.0
- TP-Link Systems Inc. HB710(US2) V1.6/1.0
- TP-Link Systems Inc. HB710(EU1) 1.0
- TP-Link Systems Inc. HB610(US2) V2.6/2.0
- TP-Link Systems Inc. HB610(EU1)
- TP-Link Systems Inc. HB610(CA) V2.0
- TP-Link Systems Inc. HB410( EU1) 1.0
Weakness type
Related vulnerabilities
- CVE-2026-87492 — Incorrect authorization in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially exe
- CVE-2026-87570 — Incorrect authorization in SiteIsolation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compr
- CVE-2026-87544 — Incorrect authorization in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system
- CVE-2026-79708 — Incorrect Authorization in GitLab
- CVE-2026-87481 — Incorrect authorization in WebView in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker who h
- CVE-2026-87644 — Incorrect authorization in Views in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker who had
- CVE-2026-87505 — Incorrect authorization in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromi
- CVE-2026-87499 — Incorrect authorization in Network in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised