TP-Link Aginet Devices Suffer Multiple High-Severity Vulnerabilities
A series of critical vulnerabilities in TP-Link's ISP-managed Aginet networking devices could allow attackers to bypass authentication, escalate privileges, and gain full control.

TP-Link has announced the discovery of multiple high-severity vulnerabilities affecting its Aginet line of networking products, which are commonly deployed and managed by internet service providers (ISPs). These flaws, tracked under CVE-2025-30237 through CVE-2025-30241, pose significant risks, potentially enabling attackers to bypass authentication, escalate privileges, expose sensitive data, read arbitrary files, and execute operating system commands.
The most critical vulnerability, CVE-2025-30237, is an authentication bypass flaw in the web management interface with a CVSS v4 score of 8.7. This issue stems from broken access control, allowing an attacker on an adjacent network to send specially crafted requests to access privileged functions without valid credentials, potentially leading to complete device control.
Further exacerbating the risk, CVE-2025-30238 (CVSS 8.6) is an improper authorization vulnerability within user management functions. This flaw could permit a low-privileged authenticated user to perform administrator-level actions, such as creating new privileged accounts or altering critical device settings, thereby expanding an attacker's control.
Another significant threat, CVE-2025-30239 (CVSS 8.5), involves hardcoded cryptographic keys embedded within the device firmware. Attackers with access to the device's storage could potentially recover these keys to decrypt sensitive configuration data, including credentials and ISP-specific service settings, opening the door for further compromise.
The advisory also details CVE-2025-30240, a medium-severity arbitrary file-read vulnerability (CVSS 5.1) affecting the USB HTTPS access path. This flaw, caused by improper handling of symbolic links on external USB storage, could allow an attacker with physical access to read sensitive files from the router's filesystem.
Rounding out the critical findings is CVE-2025-30241 (CVSS 8.6), an OS command injection vulnerability. This arises from insufficient validation of user-controlled input in certain web interface components, enabling an authenticated local attacker to inject and execute commands with elevated privileges, potentially leading to full device takeover.
The affected hardware spans numerous TP-Link Aginet series, including models like HB810, HB710, EX220, EX222, EX920, EC220-G5, XX530v, and VX1800v variants. The precise impact varies based on regional models, hardware versions, ISP customizations, and installed firmware.
Remediation for these ISP-managed devices is contingent on firmware updates provided by the respective service providers. TP-Link advises users to check their router administration interfaces or ISP management applications for updates, and to contact their ISP if an update is unavailable. In the interim, users are encouraged to restrict the exposure of management interfaces, employ strong and unique administrator credentials, disable unnecessary remote management features, and maintain a secure local network environment.