目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2025-30237— TP-Link HX510 授权问题漏洞

一分钟漏洞结论

影响对象
TP-Link Systems Inc. HB810(US2) V1.0/1.6/2.0/2.6
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

TP-Link HX510是中国TP-Link公司的一款路由器。 TP-Link HX510存在授权问题漏洞,该漏洞源于Web管理界面在某些端点未一致执行身份验证检查,导致访问控制机制执行不当,未经身份验证的攻击者可发送特制请求绕过身份验证,执行特权操作并完全控制设备。

CVSS 8.7 · High EPSS 0.33% · P24

影响版本矩阵 56

厂商产品 版本范围状态
TP-Link Systems Inc. EX141(BR) V1.0/1.9 < 1.8.0 3.1.0 v608a.0 Build 250425 Rel.40905n affected
TP-Link Systems Inc. EX141(EU1) V1.0 < 1.7.0 3.1.0 v608a.0 Build 250418 Rel.8257n affected
TP-Link Systems Inc. EX141(US1) V1.0 < 1.7.0 3.1.0 v608a.0 Build 250418 Rel.8257n affected
TP-Link Systems Inc. EX220(BR) V1.0/1.20/1.28/1.29/1.8 < 0.20.0 2.0.0 v605f.0 Build 250305 Rel.14728n affected
TP-Link Systems Inc. EX220(BR) V2.0 < 0.19.0 2.0.0 v609b.0 Build 250814 Rel.49732n affected
TP-Link Systems Inc. EX220(EU1) V1.0/1.20 < 0.20.0 2.0.0 v605f.0 Build 250305 Rel.14728n affected
TP-Link Systems Inc. EX220(RU) V1.0 < 0.20.0 2.0.0 v605f.0 Build 250305 Rel.14728n affected
TP-Link Systems Inc. EX220(US1) V1.0 < 0.20.0 2.0.0 v605f.0 Build 250305 Rel.14728n affected
TP-Link Systems Inc. EX222(EU1) V1.0 < 0.20.0 2.0.0 v605f.0 Build 250305 Rel.14728n affected
TP-Link Systems Inc. EX222(KR) V1.0 < 0.20.0 2.0.0 v609b.0 Build 260427 Rel.16915 affected
TP-Link Systems Inc. EX222(US1) V1.0 < 0.20.0 2.0.0 v605f.0 Build 250305 Rel.14728n affected
TP-Link Systems Inc. EX511(BR) V2.0/2.8/2.9 < 0.9.0 3.0.0 v607e.0 Build 260520 Rel.33425n affected
TP-Link Systems Inc. EX511(EU1) V2.0 < 0.9.0 3.0.0 v607e.0 Build 260520 Rel.33425n affected
TP-Link Systems Inc. EX511(US1) V2.0 < 0.8.0 3.0.0 v607e.0 Build 260424 Rel.27419n affected
TP-Link Systems Inc. EX520(US1) V1.0 < 0.7.0 3.0.0 v60b4.0 Build 251229 Rel.84306n affected
TP-Link Systems Inc. EX520v(EU1)1.0 < 0.1.0 3.0.0 v60ee.0 Build 250310 Rel.55637n affected
TP-Link Systems Inc. EX521(US1) V1.0 < 0.3.0 3.0.0 v60e3.0 Build 250925 Rel.66797n affected
TP-Link Systems Inc. EX820v(EU1) V1.0 < 0.4.0 3.1.9 v6087.0 Build 250928 Rel.59674n affected
TP-Link Systems Inc. EX920(US2) V1.6/V1.0 < 0.8.0 3.2.2 v6080.0 Build 260309 Rel.54790n affected
TP-Link Systems Inc. HB210 Pro(EU1)1.0 < 0.5.0 3.0.0 v60d5.0 Build 250922 Rel.13742n affected
TP-Link Systems Inc. HB210 Pro(US2)1.0/1.6 < 0.8.0 3.0.0 v60d5.0 Build 260318 Rel.78363n affected
TP-Link Systems Inc. HB210(EU1) 1.0 < 0.2.0 3.0.0 v60f9.0 Build 250826 Rel.47715n affected
TP-Link Systems Inc. HB210(US2) 1.0 < 0.2.0 3.0.0 v60f9.0 Build 250826 Rel.47715n affected
TP-Link Systems Inc. HB410( EU1) 1.0 < 0.3.0 3.0.0 v60bf.0 Build 250901 Rel.45574n affected
TP-Link Systems Inc. HB610(CA) V2.0 < 0.6.0 3.0.0 v60af.0 Build 251216 Rel.46954n affected
TP-Link Systems Inc. HB610(EU1) < 0.6.0 3.0.0 v60af.0 Build 251204 Rel.20362n affected
TP-Link Systems Inc. HB610(US2) V2.6/2.0 < 0.6.0 3.0.0 v60af.0 Build 251204 Rel.20362n affected
TP-Link Systems Inc. HB710(EU1) 1.0 < 0.3.0 3.0.0 v60be.0 Build 251128 Rel.43956n affected
TP-Link Systems Inc. HB710(US2) V1.6/1.0 < 0.3.0 3.0.0 v60be.0 Build 251128 Rel.43956n affected
TP-Link Systems Inc. HB810(EU1) V2.0 < 0.10.0 3.2.2 v6095.0 Build 260306 Rel.47567n affected
TP-Link Systems Inc. HB810(US2) V1.0/1.6/2.0/2.6 < 0.9.0 3.2.2 v6095.0 Build 260717 Rel.67188n affected
TP-Link Systems Inc. HC220-G5(BR) V1.30 < 0.17.0 2.0.0 v605e.0 Build 250618 Rel.19329n affected
TP-Link Systems Inc. HC220-G5(EU1) V1.20/1.0 < 0.18.0 2.0.0 v605e.0 Build 250827 Rel.37904n affected
TP-Link Systems Inc. HC220-G5(US1) V1.0/1.6 < 0.18.0 2.0.0 v605e.0 Build 250827 Rel.37904n affected
TP-Link Systems Inc. HX141(EU1) V1.0 < 1.2.0 3.1.0 v609d.0 Build 260128 Rel.29711n affected
TP-Link Systems Inc. HX220(AU) V1.0 < 0.21.0 2.0.0 v605f.0 Build 250306 Rel.9224n affected
TP-Link Systems Inc. HX220(CA) V1.0 < 0.21.0 2.0.0 v605f.0 Build 250306 Rel.9224n affected
TP-Link Systems Inc. HX220(EU1) V1.0 < 0.21.0 2.0.0 v605f.0 Build 250306 Rel.9224n affected
TP-Link Systems Inc. HX220(US1) V1.0/1.0 < 0.21.0 2.0.0 v605f.0 Build 250306 Rel.9224n affected
TP-Link Systems Inc. HX510(AU) V1.0/2.0 < 0.14.0 3.0.0 v6065.0 Build 250822 Rel.81150n affected
TP-Link Systems Inc. HX510(CA) V1.0/2.0 < 0.14.0 3.0.0 v6065.0 Build 250822 Rel.81150n affected
TP-Link Systems Inc. HX510(EU1) V2.0 < 0.14.0 3.0.0 v6065.0 Build 250822 Rel.81150n affected
TP-Link Systems Inc. HX510(US1) V2.0 < 0.14.0 3.0.0 v6065.0 Build 250822 Rel.81150n affected
TP-Link Systems Inc. HX510(US2) 2.6 < 0.17.0 3.2.2 v6065.0 Build 260722 Rel.10662n affected
TP-Link Systems Inc. HX710 Pro(EU1) V1.0 < 0.4.0 3.1.10 v6082.0 Build 260204 Rel.49460n affected
TP-Link Systems Inc. HX710(EU1) V1.0 < 0.5.0 3.1.10 v6075.0 Build 260511 Rel.47847n affected
TP-Link Systems Inc. VX1800v(EU1) V1.0 < 0.14.0 2.0.0 v6092.0 Build 250417 Rel.24761n affected
TP-Link Systems Inc. VX420-G2h(AU) V3.0 < 0.2.0 2.0.0 v60df.0 Build 250427 Rel.38233n affected
TP-Link Systems Inc. VX800v(DE) V1.0 < 800.0.16 affected
TP-Link Systems Inc. XC220-G3v(EU1) V2.30 < 1.16.0 0.8.0 v6062.0 Build 250817 Rel.23310n affected
TP-Link Systems Inc. XC220-G3v(US1) V2.30 < 1.16.0 0.8.0 v6062.0 Build 250817 Rel.23310n affected
TP-Link Systems Inc. XX230v(BR) V1.0 < 0.16.0 3.0.0 v6066.0 Build 250423 Rel.43799n affected
TP-Link Systems Inc. XX530v(BR)v1.0 < 0.6.0 3.0.0 v6096.0 Build 250416 Rel.26048n affected
TP-Link Systems Inc. XX530v(BR)v2.0 < 0.4.0 3.1.10 v60dc.0 Build 250520 Rel.69748n affected
TP-Link Systems Inc. XX530v(EU1) < 0.3.0 3.1.10 v6107.0 Build 250425 Rel.71973n affected
TP-Link Systems Inc. XX530v(US1) < 0.6.0 3.0.0 v6096.0 Build 250416 Rel.26048n affected
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2025-30237 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
Authentication Bypass via Broken Access Control in Web Server in Multiple TP-Link Aginet Devices
来源: CVE Program / CVE List V5
Vulnerability Description
The affected TP-Link Aginet devices contain a flaw in the web management interface where authentication checks are not consistently enforced on certain endpoints. An attacker can send specially crafted requests to bypass authentication and directly invoke privileged functionality without valid credentials. This issue arises from improper enforcement of access control mechanisms on sensitive operations. Successful exploitation may allow an unauthenticated attacker to execute privileged operations and gain full control of the device.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
来源: CVE Program / CVE List V5
Vulnerability Type
授权机制缺失
来源: CVE Program / CVE List V5
Vulnerability Title
TP-Link HX510 授权问题漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
TP-Link HX510是中国TP-Link公司的一款路由器。 TP-Link HX510存在授权问题漏洞,该漏洞源于Web管理界面在某些端点未一致执行身份验证检查,导致访问控制机制执行不当,未经身份验证的攻击者可发送特制请求绕过身份验证,执行特权操作并完全控制设备。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

受影响产品

厂商 产品 影响版本 CPE 订阅
TP-Link Systems Inc. HB810(US2) V1.0/1.6/2.0/2.6 0 ~ 0.9.0 3.2.2 v6095.0 Build 260717 Rel.67188n -
TP-Link Systems Inc. HB810(EU1) V2.0 0 ~ 0.10.0 3.2.2 v6095.0 Build 260306 Rel.47567n -
TP-Link Systems Inc. HB710(US2) V1.6/1.0 0 ~ 0.3.0 3.0.0 v60be.0 Build 251128 Rel.43956n -
TP-Link Systems Inc. HB710(EU1) 1.0 0 ~ 0.3.0 3.0.0 v60be.0 Build 251128 Rel.43956n -
TP-Link Systems Inc. HB610(US2) V2.6/2.0 0 ~ 0.6.0 3.0.0 v60af.0 Build 251204 Rel.20362n -
TP-Link Systems Inc. HB610(EU1) 0 ~ 0.6.0 3.0.0 v60af.0 Build 251204 Rel.20362n -
TP-Link Systems Inc. HB610(CA) V2.0 0 ~ 0.6.0 3.0.0 v60af.0 Build 251216 Rel.46954n -
TP-Link Systems Inc. HB410( EU1) 1.0 0 ~ 0.3.0 3.0.0 v60bf.0 Build 250901 Rel.45574n -
TP-Link Systems Inc. HB210(US2) 1.0 0 ~ 0.2.0 3.0.0 v60f9.0 Build 250826 Rel.47715n -
TP-Link Systems Inc. HB210(EU1) 1.0 0 ~ 0.2.0 3.0.0 v60f9.0 Build 250826 Rel.47715n -
TP-Link Systems Inc. HB210 Pro(EU1)1.0 0 ~ 0.5.0 3.0.0 v60d5.0 Build 250922 Rel.13742n -
TP-Link Systems Inc. HB210 Pro(US2)1.0/1.6 0 ~ 0.8.0 3.0.0 v60d5.0 Build 260318 Rel.78363n -
TP-Link Systems Inc. HX510(US1) V2.0 0 ~ 0.14.0 3.0.0 v6065.0 Build 250822 Rel.81150n -
TP-Link Systems Inc. HX510(EU1) V2.0 0 ~ 0.14.0 3.0.0 v6065.0 Build 250822 Rel.81150n -
TP-Link Systems Inc. HX510(CA) V1.0/2.0 0 ~ 0.14.0 3.0.0 v6065.0 Build 250822 Rel.81150n -
TP-Link Systems Inc. HX510(AU) V1.0/2.0 0 ~ 0.14.0 3.0.0 v6065.0 Build 250822 Rel.81150n -
TP-Link Systems Inc. HX510(US2) 2.6 0 ~ 0.17.0 3.2.2 v6065.0 Build 260722 Rel.10662n -
TP-Link Systems Inc. HX710(EU1) V1.0 0 ~ 0.5.0 3.1.10 v6075.0 Build 260511 Rel.47847n -
TP-Link Systems Inc. HX710 Pro(EU1) V1.0 0 ~ 0.4.0 3.1.10 v6082.0 Build 260204 Rel.49460n -
TP-Link Systems Inc. HX220(US1) V1.0/1.0 0 ~ 0.21.0 2.0.0 v605f.0 Build 250306 Rel.9224n -
TP-Link Systems Inc. HX220(EU1) V1.0 0 ~ 0.21.0 2.0.0 v605f.0 Build 250306 Rel.9224n -
TP-Link Systems Inc. HX220(CA) V1.0 0 ~ 0.21.0 2.0.0 v605f.0 Build 250306 Rel.9224n -
TP-Link Systems Inc. HX220(AU) V1.0 0 ~ 0.21.0 2.0.0 v605f.0 Build 250306 Rel.9224n -
TP-Link Systems Inc. HX141(EU1) V1.0 0 ~ 1.2.0 3.1.0 v609d.0 Build 260128 Rel.29711n -
TP-Link Systems Inc. HC220-G5(US1) V1.0/1.6 0 ~ 0.18.0 2.0.0 v605e.0 Build 250827 Rel.37904n -
TP-Link Systems Inc. HC220-G5(EU1) V1.20/1.0 0 ~ 0.18.0 2.0.0 v605e.0 Build 250827 Rel.37904n -
TP-Link Systems Inc. HC220-G5(BR) V1.30 0 ~ 0.17.0 2.0.0 v605e.0 Build 250618 Rel.19329n -
TP-Link Systems Inc. EX141(BR) V1.0/1.9 0 ~ 1.8.0 3.1.0 v608a.0 Build 250425 Rel.40905n -
TP-Link Systems Inc. EX141(EU1) V1.0 0 ~ 1.7.0 3.1.0 v608a.0 Build 250418 Rel.8257n -
TP-Link Systems Inc. EX141(US1) V1.0 0 ~ 1.7.0 3.1.0 v608a.0 Build 250418 Rel.8257n -

二、漏洞 CVE-2025-30237 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2025-30237 的情报信息

请登录查看更多情报信息。

CVE-2025-30237 厂商安全公告 (1)

同批安全公告 · TP-Link Systems Inc. · 2026-08-10 · 共 6 条

CVE-2025-30241 8.6 HIGH TP-Link HX510 命令注入漏洞
CVE-2025-30238 8.6 HIGH TP-Link HX510 授权问题漏洞
CVE-2025-30239 8.5 HIGH TP-Link HX510 加密问题漏洞
CVE-2026-12339 6.9 MEDIUM TP-Link TL-MR6400 路径遍历漏洞
CVE-2025-30240 5.1 MEDIUM TP-Link HX510 后置链接漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2025-30237

暂无评论


发表评论