Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2025-30237— Authentication Bypass via Broken Access Control in Web Server in Multiple TP-Link Aginet Devices

Quick assessment

Affected
TP-Link Systems Inc. HB810(US2) V1.0/1.6/2.0/2.6
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

TP-Link HX510是中国TP-Link公司的一款路由器。 TP-Link HX510存在授权问题漏洞,该漏洞源于Web管理界面在某些端点未一致执行身份验证检查,导致访问控制机制执行不当,未经身份验证的攻击者可发送特制请求绕过身份验证,执行特权操作并完全控制设备。

CVSS 8.7 · High EPSS 0.33% · P24

Affected Version Matrix 56

VendorProduct Version RangeStatus
TP-Link Systems Inc. EX141(BR) V1.0/1.9 < 1.8.0 3.1.0 v608a.0 Build 250425 Rel.40905n affected
TP-Link Systems Inc. EX141(EU1) V1.0 < 1.7.0 3.1.0 v608a.0 Build 250418 Rel.8257n affected
TP-Link Systems Inc. EX141(US1) V1.0 < 1.7.0 3.1.0 v608a.0 Build 250418 Rel.8257n affected
TP-Link Systems Inc. EX220(BR) V1.0/1.20/1.28/1.29/1.8 < 0.20.0 2.0.0 v605f.0 Build 250305 Rel.14728n affected
TP-Link Systems Inc. EX220(BR) V2.0 < 0.19.0 2.0.0 v609b.0 Build 250814 Rel.49732n affected
TP-Link Systems Inc. EX220(EU1) V1.0/1.20 < 0.20.0 2.0.0 v605f.0 Build 250305 Rel.14728n affected
TP-Link Systems Inc. EX220(RU) V1.0 < 0.20.0 2.0.0 v605f.0 Build 250305 Rel.14728n affected
TP-Link Systems Inc. EX220(US1) V1.0 < 0.20.0 2.0.0 v605f.0 Build 250305 Rel.14728n affected
TP-Link Systems Inc. EX222(EU1) V1.0 < 0.20.0 2.0.0 v605f.0 Build 250305 Rel.14728n affected
TP-Link Systems Inc. EX222(KR) V1.0 < 0.20.0 2.0.0 v609b.0 Build 260427 Rel.16915 affected
TP-Link Systems Inc. EX222(US1) V1.0 < 0.20.0 2.0.0 v605f.0 Build 250305 Rel.14728n affected
TP-Link Systems Inc. EX511(BR) V2.0/2.8/2.9 < 0.9.0 3.0.0 v607e.0 Build 260520 Rel.33425n affected
TP-Link Systems Inc. EX511(EU1) V2.0 < 0.9.0 3.0.0 v607e.0 Build 260520 Rel.33425n affected
TP-Link Systems Inc. EX511(US1) V2.0 < 0.8.0 3.0.0 v607e.0 Build 260424 Rel.27419n affected
TP-Link Systems Inc. EX520(US1) V1.0 < 0.7.0 3.0.0 v60b4.0 Build 251229 Rel.84306n affected
TP-Link Systems Inc. EX520v(EU1)1.0 < 0.1.0 3.0.0 v60ee.0 Build 250310 Rel.55637n affected
TP-Link Systems Inc. EX521(US1) V1.0 < 0.3.0 3.0.0 v60e3.0 Build 250925 Rel.66797n affected
TP-Link Systems Inc. EX820v(EU1) V1.0 < 0.4.0 3.1.9 v6087.0 Build 250928 Rel.59674n affected
TP-Link Systems Inc. EX920(US2) V1.6/V1.0 < 0.8.0 3.2.2 v6080.0 Build 260309 Rel.54790n affected
TP-Link Systems Inc. HB210 Pro(EU1)1.0 < 0.5.0 3.0.0 v60d5.0 Build 250922 Rel.13742n affected
TP-Link Systems Inc. HB210 Pro(US2)1.0/1.6 < 0.8.0 3.0.0 v60d5.0 Build 260318 Rel.78363n affected
TP-Link Systems Inc. HB210(EU1) 1.0 < 0.2.0 3.0.0 v60f9.0 Build 250826 Rel.47715n affected
TP-Link Systems Inc. HB210(US2) 1.0 < 0.2.0 3.0.0 v60f9.0 Build 250826 Rel.47715n affected
TP-Link Systems Inc. HB410( EU1) 1.0 < 0.3.0 3.0.0 v60bf.0 Build 250901 Rel.45574n affected
TP-Link Systems Inc. HB610(CA) V2.0 < 0.6.0 3.0.0 v60af.0 Build 251216 Rel.46954n affected
TP-Link Systems Inc. HB610(EU1) < 0.6.0 3.0.0 v60af.0 Build 251204 Rel.20362n affected
TP-Link Systems Inc. HB610(US2) V2.6/2.0 < 0.6.0 3.0.0 v60af.0 Build 251204 Rel.20362n affected
TP-Link Systems Inc. HB710(EU1) 1.0 < 0.3.0 3.0.0 v60be.0 Build 251128 Rel.43956n affected
TP-Link Systems Inc. HB710(US2) V1.6/1.0 < 0.3.0 3.0.0 v60be.0 Build 251128 Rel.43956n affected
TP-Link Systems Inc. HB810(EU1) V2.0 < 0.10.0 3.2.2 v6095.0 Build 260306 Rel.47567n affected
TP-Link Systems Inc. HB810(US2) V1.0/1.6/2.0/2.6 < 0.9.0 3.2.2 v6095.0 Build 260717 Rel.67188n affected
TP-Link Systems Inc. HC220-G5(BR) V1.30 < 0.17.0 2.0.0 v605e.0 Build 250618 Rel.19329n affected
TP-Link Systems Inc. HC220-G5(EU1) V1.20/1.0 < 0.18.0 2.0.0 v605e.0 Build 250827 Rel.37904n affected
TP-Link Systems Inc. HC220-G5(US1) V1.0/1.6 < 0.18.0 2.0.0 v605e.0 Build 250827 Rel.37904n affected
TP-Link Systems Inc. HX141(EU1) V1.0 < 1.2.0 3.1.0 v609d.0 Build 260128 Rel.29711n affected
TP-Link Systems Inc. HX220(AU) V1.0 < 0.21.0 2.0.0 v605f.0 Build 250306 Rel.9224n affected
TP-Link Systems Inc. HX220(CA) V1.0 < 0.21.0 2.0.0 v605f.0 Build 250306 Rel.9224n affected
TP-Link Systems Inc. HX220(EU1) V1.0 < 0.21.0 2.0.0 v605f.0 Build 250306 Rel.9224n affected
TP-Link Systems Inc. HX220(US1) V1.0/1.0 < 0.21.0 2.0.0 v605f.0 Build 250306 Rel.9224n affected
TP-Link Systems Inc. HX510(AU) V1.0/2.0 < 0.14.0 3.0.0 v6065.0 Build 250822 Rel.81150n affected
TP-Link Systems Inc. HX510(CA) V1.0/2.0 < 0.14.0 3.0.0 v6065.0 Build 250822 Rel.81150n affected
TP-Link Systems Inc. HX510(EU1) V2.0 < 0.14.0 3.0.0 v6065.0 Build 250822 Rel.81150n affected
TP-Link Systems Inc. HX510(US1) V2.0 < 0.14.0 3.0.0 v6065.0 Build 250822 Rel.81150n affected
TP-Link Systems Inc. HX510(US2) 2.6 < 0.17.0 3.2.2 v6065.0 Build 260722 Rel.10662n affected
TP-Link Systems Inc. HX710 Pro(EU1) V1.0 < 0.4.0 3.1.10 v6082.0 Build 260204 Rel.49460n affected
TP-Link Systems Inc. HX710(EU1) V1.0 < 0.5.0 3.1.10 v6075.0 Build 260511 Rel.47847n affected
TP-Link Systems Inc. VX1800v(EU1) V1.0 < 0.14.0 2.0.0 v6092.0 Build 250417 Rel.24761n affected
TP-Link Systems Inc. VX420-G2h(AU) V3.0 < 0.2.0 2.0.0 v60df.0 Build 250427 Rel.38233n affected
TP-Link Systems Inc. VX800v(DE) V1.0 < 800.0.16 affected
TP-Link Systems Inc. XC220-G3v(EU1) V2.30 < 1.16.0 0.8.0 v6062.0 Build 250817 Rel.23310n affected
TP-Link Systems Inc. XC220-G3v(US1) V2.30 < 1.16.0 0.8.0 v6062.0 Build 250817 Rel.23310n affected
TP-Link Systems Inc. XX230v(BR) V1.0 < 0.16.0 3.0.0 v6066.0 Build 250423 Rel.43799n affected
TP-Link Systems Inc. XX530v(BR)v1.0 < 0.6.0 3.0.0 v6096.0 Build 250416 Rel.26048n affected
TP-Link Systems Inc. XX530v(BR)v2.0 < 0.4.0 3.1.10 v60dc.0 Build 250520 Rel.69748n affected
TP-Link Systems Inc. XX530v(EU1) < 0.3.0 3.1.10 v6107.0 Build 250425 Rel.71973n affected
TP-Link Systems Inc. XX530v(US1) < 0.6.0 3.0.0 v6096.0 Build 250416 Rel.26048n affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2025-30237

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Authentication Bypass via Broken Access Control in Web Server in Multiple TP-Link Aginet Devices
Source: CVE Program / CVE List V5
Vulnerability Description
The affected TP-Link Aginet devices contain a flaw in the web management interface where authentication checks are not consistently enforced on certain endpoints. An attacker can send specially crafted requests to bypass authentication and directly invoke privileged functionality without valid credentials. This issue arises from improper enforcement of access control mechanisms on sensitive operations. Successful exploitation may allow an unauthenticated attacker to execute privileged operations and gain full control of the device.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制缺失
Source: CVE Program / CVE List V5
Vulnerability Title
TP-Link HX510 授权问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
TP-Link HX510是中国TP-Link公司的一款路由器。 TP-Link HX510存在授权问题漏洞,该漏洞源于Web管理界面在某些端点未一致执行身份验证检查,导致访问控制机制执行不当,未经身份验证的攻击者可发送特制请求绕过身份验证,执行特权操作并完全控制设备。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
TP-Link Systems Inc. HB810(US2) V1.0/1.6/2.0/2.6 0 ~ 0.9.0 3.2.2 v6095.0 Build 260717 Rel.67188n -
TP-Link Systems Inc. HB810(EU1) V2.0 0 ~ 0.10.0 3.2.2 v6095.0 Build 260306 Rel.47567n -
TP-Link Systems Inc. HB710(US2) V1.6/1.0 0 ~ 0.3.0 3.0.0 v60be.0 Build 251128 Rel.43956n -
TP-Link Systems Inc. HB710(EU1) 1.0 0 ~ 0.3.0 3.0.0 v60be.0 Build 251128 Rel.43956n -
TP-Link Systems Inc. HB610(US2) V2.6/2.0 0 ~ 0.6.0 3.0.0 v60af.0 Build 251204 Rel.20362n -
TP-Link Systems Inc. HB610(EU1) 0 ~ 0.6.0 3.0.0 v60af.0 Build 251204 Rel.20362n -
TP-Link Systems Inc. HB610(CA) V2.0 0 ~ 0.6.0 3.0.0 v60af.0 Build 251216 Rel.46954n -
TP-Link Systems Inc. HB410( EU1) 1.0 0 ~ 0.3.0 3.0.0 v60bf.0 Build 250901 Rel.45574n -
TP-Link Systems Inc. HB210(US2) 1.0 0 ~ 0.2.0 3.0.0 v60f9.0 Build 250826 Rel.47715n -
TP-Link Systems Inc. HB210(EU1) 1.0 0 ~ 0.2.0 3.0.0 v60f9.0 Build 250826 Rel.47715n -
TP-Link Systems Inc. HB210 Pro(EU1)1.0 0 ~ 0.5.0 3.0.0 v60d5.0 Build 250922 Rel.13742n -
TP-Link Systems Inc. HB210 Pro(US2)1.0/1.6 0 ~ 0.8.0 3.0.0 v60d5.0 Build 260318 Rel.78363n -
TP-Link Systems Inc. HX510(US1) V2.0 0 ~ 0.14.0 3.0.0 v6065.0 Build 250822 Rel.81150n -
TP-Link Systems Inc. HX510(EU1) V2.0 0 ~ 0.14.0 3.0.0 v6065.0 Build 250822 Rel.81150n -
TP-Link Systems Inc. HX510(CA) V1.0/2.0 0 ~ 0.14.0 3.0.0 v6065.0 Build 250822 Rel.81150n -
TP-Link Systems Inc. HX510(AU) V1.0/2.0 0 ~ 0.14.0 3.0.0 v6065.0 Build 250822 Rel.81150n -
TP-Link Systems Inc. HX510(US2) 2.6 0 ~ 0.17.0 3.2.2 v6065.0 Build 260722 Rel.10662n -
TP-Link Systems Inc. HX710(EU1) V1.0 0 ~ 0.5.0 3.1.10 v6075.0 Build 260511 Rel.47847n -
TP-Link Systems Inc. HX710 Pro(EU1) V1.0 0 ~ 0.4.0 3.1.10 v6082.0 Build 260204 Rel.49460n -
TP-Link Systems Inc. HX220(US1) V1.0/1.0 0 ~ 0.21.0 2.0.0 v605f.0 Build 250306 Rel.9224n -
TP-Link Systems Inc. HX220(EU1) V1.0 0 ~ 0.21.0 2.0.0 v605f.0 Build 250306 Rel.9224n -
TP-Link Systems Inc. HX220(CA) V1.0 0 ~ 0.21.0 2.0.0 v605f.0 Build 250306 Rel.9224n -
TP-Link Systems Inc. HX220(AU) V1.0 0 ~ 0.21.0 2.0.0 v605f.0 Build 250306 Rel.9224n -
TP-Link Systems Inc. HX141(EU1) V1.0 0 ~ 1.2.0 3.1.0 v609d.0 Build 260128 Rel.29711n -
TP-Link Systems Inc. HC220-G5(US1) V1.0/1.6 0 ~ 0.18.0 2.0.0 v605e.0 Build 250827 Rel.37904n -
TP-Link Systems Inc. HC220-G5(EU1) V1.20/1.0 0 ~ 0.18.0 2.0.0 v605e.0 Build 250827 Rel.37904n -
TP-Link Systems Inc. HC220-G5(BR) V1.30 0 ~ 0.17.0 2.0.0 v605e.0 Build 250618 Rel.19329n -
TP-Link Systems Inc. EX141(BR) V1.0/1.9 0 ~ 1.8.0 3.1.0 v608a.0 Build 250425 Rel.40905n -
TP-Link Systems Inc. EX141(EU1) V1.0 0 ~ 1.7.0 3.1.0 v608a.0 Build 250418 Rel.8257n -
TP-Link Systems Inc. EX141(US1) V1.0 0 ~ 1.7.0 3.1.0 v608a.0 Build 250418 Rel.8257n -

II. Public POCs for CVE-2025-30237

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-30237

请登录查看更多情报信息。

Vendor Advisories for CVE-2025-30237 (1)

Same Patch Batch · TP-Link Systems Inc. · 2026-08-10 · 6 CVEs total

CVE-2025-30241 8.6 HIGH OS Command Injection in Web Interface in Multiple TP-Link Aginet Devices
CVE-2025-30238 8.6 HIGH Privilege Escalation via Improper Authorization in User Management in multiple TP-Link Agi
CVE-2025-30239 8.5 HIGH Sensitive Data Exposure due to Hardcoded Cryptographic Keys in Multiple TP-Link Aginet Dev
CVE-2026-12339 6.9 MEDIUM Authenticated Arbitrary File Write Vulnerability in multiple devices
CVE-2025-30240 5.1 MEDIUM Arbitrary File Read via Improper Symlink Handling in USB HTTPS Access Path in multiple TP-

IV. Related Vulnerabilities

V. Comments for CVE-2025-30237

No comments yet


Leave a comment