Certain web
interface components in affected TP-Link Aginet devices do not validate and sanitize user-supplied input properly before
passing it to system-level command execution functions.  An authenticated adjacent attacker may inject
specially crafted input to execute arbitrary operation system commands with
elevated privileges.









Successful
exploitation may allow execution of arbitrary system commands, potentially
leading to full device compromise.

Project Subscriptions

Vendors Products
Tp-link Subscribe
Eb210 Pro(eu1) 1.0 Subscribe
Eb210 Pro(us1) 1.0 Subscribe
Eb810v(eu1) V1.0 Subscribe
Ex220(br) V1.0/1.20/1.28/1.29/1.8 Subscribe
Ex220(br) V2.0 Subscribe
Ex220(eu1) V1.0/1.20 Subscribe
Ex220(ru) V1.0 Subscribe
Ex220(us1) V1.0 Subscribe
Ex222(eu1) V1.0 Subscribe
Ex222(kr) V1.0 Subscribe
Ex222(us1) V1.0 Subscribe
Ex520v(eu1)1.0 Subscribe
Ex820v(eu1) V1.0 Subscribe
Ex920(us2) V1.6/v1.0 Subscribe
Hb210(eu1) 1.0 Subscribe
Hb210(us2) 1.0 Subscribe
Hb210 Pro(eu1)1.0 Subscribe
Hb210 Pro(us2)1.0/1.6 Subscribe
Hb410( Eu1) 1.0 Subscribe
Hb610(ca) V2.0 Subscribe
Hb610(eu1) Subscribe
Hb610(us2) V2.6/2.0 Subscribe
Hb710(eu1) 1.0 Subscribe
Hb710(us2) V1.6/1.0 Subscribe
Hb810(eu1) V2.0 Subscribe
Hb810(us2) V1.0/1.6/2.0/2.6 Subscribe
Vx420-g2h(au) V3.0 Subscribe
Vx800v(de) V1.0 Subscribe
Xx230v(br) V1.0 Subscribe
Xx530v(br)v2.0 Subscribe
Xx530v(eu1) Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 12 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Tp-link
Tp-link eb210 Pro(eu1) 1.0
Tp-link eb210 Pro(us1) 1.0
Tp-link eb810v(eu1) V1.0
Tp-link ex220(br) V1.0/1.20/1.28/1.29/1.8
Tp-link ex220(br) V2.0
Tp-link ex220(eu1) V1.0/1.20
Tp-link ex220(ru) V1.0
Tp-link ex220(us1) V1.0
Tp-link ex222(eu1) V1.0
Tp-link ex222(kr) V1.0
Tp-link ex222(us1) V1.0
Tp-link ex520v(eu1)1.0
Tp-link ex820v(eu1) V1.0
Tp-link ex920(us2) V1.6/v1.0
Tp-link hb210(eu1) 1.0
Tp-link hb210(us2) 1.0
Tp-link hb210 Pro(eu1)1.0
Tp-link hb210 Pro(us2)1.0/1.6
Tp-link hb410( Eu1) 1.0
Tp-link hb610(ca) V2.0
Tp-link hb610(eu1)
Tp-link hb610(us2) V2.6/2.0
Tp-link hb710(eu1) 1.0
Tp-link hb710(us2) V1.6/1.0
Tp-link hb810(eu1) V2.0
Tp-link hb810(us2) V1.0/1.6/2.0/2.6
Tp-link vx420-g2h(au) V3.0
Tp-link vx800v(de) V1.0
Tp-link xx230v(br) V1.0
Tp-link xx530v(br)v2.0
Tp-link xx530v(eu1)
Vendors & Products Tp-link
Tp-link eb210 Pro(eu1) 1.0
Tp-link eb210 Pro(us1) 1.0
Tp-link eb810v(eu1) V1.0
Tp-link ex220(br) V1.0/1.20/1.28/1.29/1.8
Tp-link ex220(br) V2.0
Tp-link ex220(eu1) V1.0/1.20
Tp-link ex220(ru) V1.0
Tp-link ex220(us1) V1.0
Tp-link ex222(eu1) V1.0
Tp-link ex222(kr) V1.0
Tp-link ex222(us1) V1.0
Tp-link ex520v(eu1)1.0
Tp-link ex820v(eu1) V1.0
Tp-link ex920(us2) V1.6/v1.0
Tp-link hb210(eu1) 1.0
Tp-link hb210(us2) 1.0
Tp-link hb210 Pro(eu1)1.0
Tp-link hb210 Pro(us2)1.0/1.6
Tp-link hb410( Eu1) 1.0
Tp-link hb610(ca) V2.0
Tp-link hb610(eu1)
Tp-link hb610(us2) V2.6/2.0
Tp-link hb710(eu1) 1.0
Tp-link hb710(us2) V1.6/1.0
Tp-link hb810(eu1) V2.0
Tp-link hb810(us2) V1.0/1.6/2.0/2.6
Tp-link vx420-g2h(au) V3.0
Tp-link vx800v(de) V1.0
Tp-link xx230v(br) V1.0
Tp-link xx530v(br)v2.0
Tp-link xx530v(eu1)

Mon, 10 Aug 2026 22:45:00 +0000

Type Values Removed Values Added
Description Certain web interface components in affected TP-Link Aginet devices do not validate and sanitize user-supplied input properly before passing it to system-level command execution functions.  An authenticated adjacent attacker may inject specially crafted input to execute arbitrary operation system commands with elevated privileges. Successful exploitation may allow execution of arbitrary system commands, potentially leading to full device compromise.
Title OS Command Injection in Web Interface in Multiple TP-Link Aginet Devices
Weaknesses CWE-78
References
Metrics cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: TPLink

Published:

Updated: 2026-08-12T18:56:29.140Z

Reserved: 2025-03-19T11:09:33.245Z

Link: CVE-2025-30241

cve-icon Vulnrichment

Updated: 2026-08-12T18:56:24.821Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-10T23:16:50.670

Modified: 2026-08-18T15:04:46.610

Link: CVE-2025-30241

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-11T14:21:20Z

Weaknesses