TP-Link has recently identified multiple high-severity vulnerabilities in its Aginet series of networking products, which include mesh systems, routers, PON devices, and xDSL modems. These flaws could enable attackers with network access to bypass authentication, escalate privileges, access sensitive information, read device files, and execute operating system commands.
The security advisory, updated on August 10, 2026, lists the vulnerabilities as CVE-2025-30237 through CVE-2025-30241. These products are typically supplied, configured, and updated by internet service providers (ISPs), meaning firmware availability may vary by operator and region.
Details of the Vulnerabilities
The most critical of these vulnerabilities, CVE-2025-30237, is an authentication bypass issue in the web management interface, carrying a CVSS v4 score of 8.7. This flaw arises from inadequate access control on certain endpoints, allowing an attacker on an adjacent network to send specially crafted requests to access privileged functions without valid credentials. Exploiting this vulnerability could grant an unauthenticated attacker full control over the affected device.
CVE-2025-30238, rated 8.6, is an improper authorization flaw in user-management functions. A low-privileged authenticated user could perform administrator-level actions, such as creating privileged accounts or altering critical device settings. This could enable an attacker with limited access to expand their control over a router or mesh node.
Another significant issue, CVE-2025-30239, involves hardcoded cryptographic keys stored in the firmware, with a CVSS score of 8.5. An attacker with access to the device’s storage could recover these embedded keys and decrypt protected configuration data, potentially exposing credentials and ISP-related service settings, leading to further compromise.
CVE-2025-30240 is a medium-severity arbitrary file-read vulnerability with a CVSS score of 5.1. This flaw affects the USB HTTPS access path and results from improper handling of symbolic links on external USB storage. An individual with physical access to the device could create a malicious symbolic link on a supported medium to access sensitive files in the router filesystem.
The final issue, CVE-2025-30241, is an OS command injection vulnerability with a severity rating of 8.6. It exists because certain web-interface components fail to properly validate user-controlled input before passing it to system-level command functions. An authenticated attacker on the local network could inject commands and execute them with elevated privileges, potentially taking complete control of the device.
Affected Devices and Mitigation
Affected hardware includes models from TP-Link’s HB, HX, HC, EB, EC, EX, XC, XX, and VX series, such as HB810, HB710, EX220, EX222, EX920, EC220-G5, XX530v, and VX1800v variants. The exact impact depends on the regional model, hardware version, ISP customizations, and installed firmware.
TP-Link has stated that remediation for ISP-managed devices will be coordinated through service providers. In many cases, updates may be installed automatically through ISP management platforms. Users should check the router administration interface or the provider’s management application for firmware updates. If an update is unavailable, customers should contact their ISP to confirm whether their device is affected and when a patched firmware release will be deployed.
Given that several flaws require local or adjacent-network access, users should also restrict exposure of management interfaces, use strong, unique administrator credentials, disable unnecessary remote management features, and prevent untrusted users from accessing the local network.
These vulnerabilities underscore the critical importance of regular firmware updates and vigilant network security practices. Users should proactively monitor for updates and implement recommended security measures to protect their devices and networks from potential exploitation.