{"api_version":"1","generated_at":"2026-08-30T20:58:04+00:00","cve":"CVE-2025-30237","urls":{"html":"https://cve.report/CVE-2025-30237","api":"https://cve.report/api/cve/CVE-2025-30237.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2025-30237","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2025-30237"},"summary":{"title":"Authentication Bypass via Broken Access Control in Web Server in Multiple TP-Link Aginet Devices","description":"The affected TP-Link Aginet devices contain a flaw in the web management interface where authentication\nchecks are not consistently enforced on certain endpoints. An attacker can send\nspecially crafted requests to bypass authentication and directly invoke\nprivileged functionality without valid credentials. This issue arises from\nimproper enforcement of access control mechanisms on sensitive operations.\n\n\n\n\n\nSuccessful\nexploitation may allow an unauthenticated attacker to execute privileged\noperations and gain full control of the device.","state":"PUBLISHED","assigner":"TPLink","published_at":"2026-08-10 23:16:48","updated_at":"2026-08-18 15:04:46"},"problem_types":["CWE-862","CWE-862 CWE-862: Missing Authorization"],"metrics":[{"version":"4.0","source":"f23511db-6c3e-4e32-a477-6aa17d310630","type":"Secondary","score":"8.7","severity":"HIGH","vector":"CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","data":{"version":"4.0","vectorString":"CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"ADJACENT","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}},{"version":"4.0","source":"CNA","type":"CVSS","score":"8.7","severity":"HIGH","vector":"CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","data":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"ADJACENT","baseScore":8.7,"baseSeverity":"HIGH","exploitMaturity":"NOT_DEFINED","privilegesRequired":"NONE","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnerabilityResponseEffort":"NOT_DEFINED"}}],"references":[{"url":"https://www.tp-link.com/us/support/faq/5239/","name":"https://www.tp-link.com/us/support/faq/5239/","refsource":"f23511db-6c3e-4e32-a477-6aa17d310630","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2025-30237","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2025-30237","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"TP-Link Systems Inc.","product":"HB810(US2) V1.0/1.6/2.0/2.6","version":"affected 0.9.0 3.2.2 v6095.0 Build 260717 Rel.67188n custom","platforms":[]},{"source":"CNA","vendor":"TP-Link Systems Inc.","product":"HB810(EU1) V2.0","version":"affected 0.10.0 3.2.2 v6095.0 Build 260306 Rel.47567n custom","platforms":[]},{"source":"CNA","vendor":"TP-Link Systems Inc.","product":"HB710(US2) V1.6/1.0","version":"affected 0.3.0 3.0.0 v60be.0 Build 251128 Rel.43956n custom","platforms":[]},{"source":"CNA","vendor":"TP-Link Systems Inc.","product":"HB710(EU1) 1.0","version":"affected 0.3.0 3.0.0 v60be.0 Build 251128 Rel.43956n custom","platforms":[]},{"source":"CNA","vendor":"TP-Link Systems Inc.","product":"HB610(US2) V2.6/2.0","version":"affected 0.6.0 3.0.0 v60af.0 Build 251204 Rel.20362n custom","platforms":[]},{"source":"CNA","vendor":"TP-Link Systems Inc.","product":"HB610(EU1)","version":"affected 0.6.0 3.0.0 v60af.0 Build 251204 Rel.20362n custom","platforms":[]},{"source":"CNA","vendor":"TP-Link Systems Inc.","product":"HB610(CA) V2.0","version":"affected 0.6.0 3.0.0 v60af.0 Build 251216 Rel.46954n custom","platforms":[]},{"source":"CNA","vendor":"TP-Link Systems Inc.","product":"HB410( EU1) 1.0","version":"affected 0.3.0 3.0.0 v60bf.0 Build 250901 Rel.45574n custom","platforms":[]},{"source":"CNA","vendor":"TP-Link Systems Inc.","product":"HB210(US2) 1.0","version":"affected 0.2.0 3.0.0 v60f9.0 Build 250826 Rel.47715n custom","platforms":[]},{"source":"CNA","vendor":"TP-Link Systems Inc.","product":"HB210(EU1) 1.0","version":"affected 0.2.0 3.0.0 v60f9.0 Build 250826 Rel.47715n custom","platforms":[]},{"source":"CNA","vendor":"TP-Link Systems Inc.","product":"HB210 Pro(EU1)1.0","version":"affected 0.5.0 3.0.0 v60d5.0 Build 250922 Rel.13742n custom","platforms":[]},{"source":"CNA","vendor":"TP-Link Systems Inc.","product":"HB210 Pro(US2)1.0/1.6","version":"affected 0.8.0 3.0.0 v60d5.0 Build 260318 Rel.78363n custom","platforms":[]},{"source":"CNA","vendor":"TP-Link Systems Inc.","product":"HX510(US1) V2.0","version":"affected 0.14.0 3.0.0 v6065.0 Build 250822 Rel.81150n custom","platforms":[]},{"source":"CNA","vendor":"TP-Link Systems Inc.","product":"HX510(EU1) V2.0","version":"affected 0.14.0 3.0.0 v6065.0 Build 250822 Rel.81150n custom","platforms":[]},{"source":"CNA","vendor":"TP-Link Systems Inc.","product":"HX510(CA) V1.0/2.0","version":"affected 0.14.0 3.0.0 v6065.0 Build 250822 Rel.81150n custom","platforms":[]},{"source":"CNA","vendor":"TP-Link Systems Inc.","product":"HX510(AU) V1.0/2.0","version":"affected 0.14.0 3.0.0 v6065.0 Build 250822 Rel.81150n custom","platforms":[]},{"source":"CNA","vendor":"TP-Link Systems Inc.","product":"HX510(US2) 2.6","version":"affected 0.17.0 3.2.2 v6065.0 Build 260722 Rel.10662n custom","platforms":[]},{"source":"CNA","vendor":"TP-Link Systems Inc.","product":"HX710(EU1) V1.0","version":"affected 0.5.0 3.1.10 v6075.0 Build 260511 Rel.47847n custom","platforms":[]},{"source":"CNA","vendor":"TP-Link Systems Inc.","product":"HX710 Pro(EU1) V1.0","version":"affected 0.4.0 3.1.10 v6082.0 Build 260204 Rel.49460n custom","platforms":[]},{"source":"CNA","vendor":"TP-Link Systems Inc.","product":"HX220(US1) V1.0/1.0","version":"affected 0.21.0 2.0.0 v605f.0 Build 250306 Rel.9224n custom","platforms":[]},{"source":"CNA","vendor":"TP-Link Systems Inc.","product":"HX220(EU1) V1.0","version":"affected 0.21.0 2.0.0 v605f.0 Build 250306 Rel.9224n custom","platforms":[]},{"source":"CNA","vendor":"TP-Link Systems Inc.","product":"HX220(CA) V1.0","version":"affected 0.21.0 2.0.0 v605f.0 Build 250306 Rel.9224n custom","platforms":[]},{"source":"CNA","vendor":"TP-Link Systems Inc.","product":"HX220(AU) V1.0","version":"affected 0.21.0 2.0.0 v605f.0 Build 250306 Rel.9224n custom","platforms":[]},{"source":"CNA","vendor":"TP-Link Systems Inc.","product":"HX141(EU1) V1.0","version":"affected 1.2.0 3.1.0 v609d.0 Build 260128 Rel.29711n custom","platforms":[]},{"source":"CNA","vendor":"TP-Link Systems Inc.","product":"HC220-G5(US1) V1.0/1.6","version":"affected 0.18.0 2.0.0 v605e.0 Build 250827 Rel.37904n custom","platforms":[]},{"source":"CNA","vendor":"TP-Link Systems Inc.","product":"HC220-G5(EU1) V1.20/1.0","version":"affected 0.18.0 2.0.0 v605e.0 Build 250827 Rel.37904n custom","platforms":[]},{"source":"CNA","vendor":"TP-Link Systems Inc.","product":"HC220-G5(BR) V1.30","version":"affected 0.17.0 2.0.0 v605e.0 Build 250618 Rel.19329n custom","platforms":[]},{"source":"CNA","vendor":"TP-Link Systems Inc.","product":"EX141(BR) V1.0/1.9","version":"affected 1.8.0 3.1.0 v608a.0 Build 250425 Rel.40905n custom","platforms":[]},{"source":"CNA","vendor":"TP-Link Systems Inc.","product":"EX141(EU1) V1.0","version":"affected 1.7.0 3.1.0 v608a.0 Build 250418 Rel.8257n custom","platforms":[]},{"source":"CNA","vendor":"TP-Link Systems Inc.","product":"EX141(US1) V1.0","version":"affected 1.7.0 3.1.0 v608a.0 Build 250418 Rel.8257n custom","platforms":[]},{"source":"CNA","vendor":"TP-Link Systems Inc.","product":"EX220(BR) V1.0/1.20/1.28/1.29/1.8","version":"affected 0.20.0 2.0.0 v605f.0 Build 250305 Rel.14728n custom","platforms":[]},{"source":"CNA","vendor":"TP-Link Systems Inc.","product":"EX220(BR) V2.0","version":"affected 0.19.0 2.0.0 v609b.0 Build 250814 Rel.49732n custom","platforms":[]},{"source":"CNA","vendor":"TP-Link Systems Inc.","product":"EX220(EU1) V1.0/1.20","version":"affected 0.20.0 2.0.0 v605f.0 Build 250305 Rel.14728n custom","platforms":[]},{"source":"CNA","vendor":"TP-Link Systems Inc.","product":"EX220(RU) V1.0","version":"affected 0.20.0 2.0.0 v605f.0 Build 250305 Rel.14728n custom","platforms":[]},{"source":"CNA","vendor":"TP-Link Systems Inc.","product":"EX220(US1) V1.0","version":"affected 0.20.0 2.0.0 v605f.0 Build 250305 Rel.14728n custom","platforms":[]},{"source":"CNA","vendor":"TP-Link Systems Inc.","product":"EX222(EU1) V1.0","version":"affected 0.20.0 2.0.0 v605f.0 Build 250305 Rel.14728n custom","platforms":[]},{"source":"CNA","vendor":"TP-Link Systems Inc.","product":"EX222(KR) V1.0","version":"affected 0.20.0 2.0.0 v609b.0 Build 260427 Rel.16915 custom","platforms":[]},{"source":"CNA","vendor":"TP-Link Systems Inc.","product":"EX222(US1) V1.0","version":"affected 0.20.0 2.0.0 v605f.0 Build 250305 Rel.14728n custom","platforms":[]},{"source":"CNA","vendor":"TP-Link Systems Inc.","product":"EX511(BR) V2.0/2.8/2.9","version":"affected 0.9.0 3.0.0 v607e.0 Build 260520 Rel.33425n custom","platforms":[]},{"source":"CNA","vendor":"TP-Link Systems Inc.","product":"EX511(EU1) V2.0","version":"affected 0.9.0 3.0.0 v607e.0 Build 260520 Rel.33425n custom","platforms":[]},{"source":"CNA","vendor":"TP-Link Systems Inc.","product":"EX511(US1) V2.0","version":"affected 0.8.0 3.0.0 v607e.0 Build 260424 Rel.27419n custom","platforms":[]},{"source":"CNA","vendor":"TP-Link Systems Inc.","product":"EX520(US1) V1.0","version":"affected 0.7.0 3.0.0 v60b4.0 Build 251229 Rel.84306n custom","platforms":[]},{"source":"CNA","vendor":"TP-Link Systems Inc.","product":"EX520v(EU1)1.0","version":"affected 0.1.0 3.0.0 v60ee.0 Build 250310 Rel.55637n custom","platforms":[]},{"source":"CNA","vendor":"TP-Link Systems Inc.","product":"EX521(US1) V1.0","version":"affected 0.3.0 3.0.0 v60e3.0 Build 250925 Rel.66797n custom","platforms":[]},{"source":"CNA","vendor":"TP-Link Systems Inc.","product":"EX820v(EU1) V1.0","version":"affected 0.4.0 3.1.9 v6087.0 Build 250928 Rel.59674n custom","platforms":[]},{"source":"CNA","vendor":"TP-Link Systems Inc.","product":"EX920(US2) V1.6/V1.0","version":"affected 0.8.0 3.2.2 v6080.0 Build 260309 Rel.54790n custom","platforms":[]},{"source":"CNA","vendor":"TP-Link Systems Inc.","product":"XC220-G3v(EU1) V2.30","version":"affected 1.16.0 0.8.0 v6062.0 Build 250817 Rel.23310n custom","platforms":[]},{"source":"CNA","vendor":"TP-Link Systems Inc.","product":"XC220-G3v(US1) V2.30","version":"affected 1.16.0 0.8.0 v6062.0 Build 250817 Rel.23310n custom","platforms":[]},{"source":"CNA","vendor":"TP-Link Systems Inc.","product":"XX530v(BR)v1.0","version":"affected 0.6.0 3.0.0 v6096.0 Build 250416 Rel.26048n custom","platforms":[]},{"source":"CNA","vendor":"TP-Link Systems Inc.","product":"XX530v(BR)v2.0","version":"affected 0.4.0 3.1.10 v60dc.0 Build 250520 Rel.69748n custom","platforms":[]},{"source":"CNA","vendor":"TP-Link Systems Inc.","product":"XX530v(US1)","version":"affected 0.6.0 3.0.0 v6096.0 Build 250416 Rel.26048n custom","platforms":[]},{"source":"CNA","vendor":"TP-Link Systems Inc.","product":"XX530v(EU1)","version":"affected 0.3.0 3.1.10 v6107.0 Build 250425 Rel.71973n custom","platforms":[]},{"source":"CNA","vendor":"TP-Link Systems Inc.","product":"XX230v(BR) V1.0","version":"affected 0.16.0 3.0.0 v6066.0 Build 250423 Rel.43799n custom","platforms":[]},{"source":"CNA","vendor":"TP-Link Systems Inc.","product":"VX800v(DE) V1.0","version":"affected 800.0.16 custom","platforms":[]},{"source":"CNA","vendor":"TP-Link Systems Inc.","product":"VX1800v(EU1) V1.0","version":"affected 0.14.0 2.0.0 v6092.0 Build 250417 Rel.24761n custom","platforms":[]},{"source":"CNA","vendor":"TP-Link Systems Inc.","product":"VX420-G2h(AU) V3.0","version":"affected 0.2.0 2.0.0 v60df.0 Build 250427 Rel.38233n custom","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Gerhard Hechenberger, Stefan Schweighofer, Constantin Schieber-Knoebl from the SEC Consult Vulnerability Lab","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2025","cve_id":"30237","cve":"CVE-2025-30237","epss":"0.002190000","percentile":"0.126350000","score_date":"2026-08-18","updated_at":"2026-08-19 00:07:28"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2025-30237","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","timestamp":"2026-08-11T14:23:38.414631Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-08-11T14:23:49.823Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"defaultStatus":"unaffected","product":"HB810(US2) V1.0/1.6/2.0/2.6","vendor":"TP-Link Systems Inc.","versions":[{"lessThan":"0.9.0 3.2.2 v6095.0 Build 260717 Rel.67188n","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"unaffected","product":"HB810(EU1) V2.0","vendor":"TP-Link Systems Inc.","versions":[{"lessThan":"0.10.0 3.2.2 v6095.0 Build 260306 Rel.47567n","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"unaffected","product":"HB710(US2) V1.6/1.0","vendor":"TP-Link Systems Inc.","versions":[{"lessThan":"0.3.0 3.0.0 v60be.0 Build 251128 Rel.43956n","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"unaffected","product":"HB710(EU1) 1.0","vendor":"TP-Link Systems Inc.","versions":[{"lessThan":"0.3.0 3.0.0 v60be.0 Build 251128 Rel.43956n","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"unaffected","product":"HB610(US2) V2.6/2.0","vendor":"TP-Link Systems Inc.","versions":[{"lessThan":"0.6.0 3.0.0 v60af.0 Build 251204 Rel.20362n","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"unaffected","product":"HB610(EU1)","vendor":"TP-Link Systems Inc.","versions":[{"lessThan":"0.6.0 3.0.0 v60af.0 Build 251204 Rel.20362n","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"unaffected","product":"HB610(CA) V2.0","vendor":"TP-Link Systems Inc.","versions":[{"lessThan":"0.6.0 3.0.0 v60af.0 Build 251216 Rel.46954n","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"unaffected","product":"HB410( EU1) 1.0","vendor":"TP-Link Systems Inc.","versions":[{"lessThan":"0.3.0 3.0.0 v60bf.0 Build 250901 Rel.45574n","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"unaffected","product":"HB210(US2) 1.0","vendor":"TP-Link Systems Inc.","versions":[{"lessThan":"0.2.0 3.0.0 v60f9.0 Build 250826 Rel.47715n","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"unaffected","product":"HB210(EU1) 1.0","vendor":"TP-Link Systems Inc.","versions":[{"lessThan":"0.2.0 3.0.0 v60f9.0 Build 250826 Rel.47715n","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"unaffected","product":"HB210 Pro(EU1)1.0","vendor":"TP-Link Systems Inc.","versions":[{"lessThan":"0.5.0 3.0.0 v60d5.0 Build 250922 Rel.13742n","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"unaffected","product":"HB210 Pro(US2)1.0/1.6","vendor":"TP-Link Systems Inc.","versions":[{"lessThan":"0.8.0 3.0.0 v60d5.0 Build 260318 Rel.78363n","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"unaffected","product":"HX510(US1) V2.0","vendor":"TP-Link Systems Inc.","versions":[{"lessThan":"0.14.0 3.0.0 v6065.0 Build 250822 Rel.81150n","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"unaffected","product":"HX510(EU1) V2.0","vendor":"TP-Link Systems Inc.","versions":[{"lessThan":"0.14.0 3.0.0 v6065.0 Build 250822 Rel.81150n","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"unaffected","product":"HX510(CA) V1.0/2.0","vendor":"TP-Link Systems Inc.","versions":[{"lessThan":"0.14.0 3.0.0 v6065.0 Build 250822 Rel.81150n","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"unaffected","product":"HX510(AU) V1.0/2.0","vendor":"TP-Link Systems Inc.","versions":[{"lessThan":"0.14.0 3.0.0 v6065.0 Build 250822 Rel.81150n","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"unaffected","product":"HX510(US2) 2.6","vendor":"TP-Link Systems Inc.","versions":[{"lessThan":"0.17.0 3.2.2 v6065.0 Build 260722 Rel.10662n","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"unaffected","product":"HX710(EU1) V1.0","vendor":"TP-Link Systems Inc.","versions":[{"lessThan":"0.5.0 3.1.10 v6075.0 Build 260511 Rel.47847n","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"unaffected","product":"HX710 Pro(EU1) V1.0","vendor":"TP-Link Systems Inc.","versions":[{"lessThan":"0.4.0 3.1.10 v6082.0 Build 260204 Rel.49460n","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"unaffected","product":"HX220(US1) V1.0/1.0","vendor":"TP-Link Systems Inc.","versions":[{"lessThan":"0.21.0 2.0.0 v605f.0 Build 250306 Rel.9224n","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"unaffected","product":"HX220(EU1) V1.0","vendor":"TP-Link Systems Inc.","versions":[{"lessThan":"0.21.0 2.0.0 v605f.0 Build 250306 Rel.9224n","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"unaffected","product":"HX220(CA) V1.0","vendor":"TP-Link Systems Inc.","versions":[{"lessThan":"0.21.0 2.0.0 v605f.0 Build 250306 Rel.9224n","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"unaffected","product":"HX220(AU) V1.0","vendor":"TP-Link Systems Inc.","versions":[{"lessThan":"0.21.0 2.0.0 v605f.0 Build 250306 Rel.9224n","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"unaffected","product":"HX141(EU1) V1.0","vendor":"TP-Link Systems Inc.","versions":[{"lessThan":"1.2.0 3.1.0 v609d.0 Build 260128 Rel.29711n","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"unaffected","product":"HC220-G5(US1) V1.0/1.6","vendor":"TP-Link Systems Inc.","versions":[{"lessThan":"0.18.0 2.0.0 v605e.0 Build 250827 Rel.37904n","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"unaffected","product":"HC220-G5(EU1) V1.20/1.0","vendor":"TP-Link Systems Inc.","versions":[{"lessThan":"0.18.0 2.0.0 v605e.0 Build 250827 Rel.37904n","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"unaffected","product":"HC220-G5(BR) V1.30","vendor":"TP-Link Systems Inc.","versions":[{"lessThan":"0.17.0 2.0.0 v605e.0 Build 250618 Rel.19329n","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"unaffected","product":"EX141(BR) V1.0/1.9","vendor":"TP-Link Systems Inc.","versions":[{"lessThan":"1.8.0 3.1.0 v608a.0 Build 250425 Rel.40905n","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"unaffected","product":"EX141(EU1) V1.0","vendor":"TP-Link Systems Inc.","versions":[{"lessThan":"1.7.0 3.1.0 v608a.0 Build 250418 Rel.8257n","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"unaffected","product":"EX141(US1) V1.0","vendor":"TP-Link Systems Inc.","versions":[{"lessThan":"1.7.0 3.1.0 v608a.0 Build 250418 Rel.8257n","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"unaffected","product":"EX220(BR) V1.0/1.20/1.28/1.29/1.8","vendor":"TP-Link Systems Inc.","versions":[{"lessThan":"0.20.0 2.0.0 v605f.0 Build 250305 Rel.14728n","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"unaffected","product":"EX220(BR) V2.0","vendor":"TP-Link Systems Inc.","versions":[{"lessThan":"0.19.0 2.0.0 v609b.0 Build 250814 Rel.49732n","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"unaffected","product":"EX220(EU1) V1.0/1.20","vendor":"TP-Link Systems Inc.","versions":[{"lessThan":"0.20.0 2.0.0 v605f.0 Build 250305 Rel.14728n","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"unaffected","product":"EX220(RU) V1.0","vendor":"TP-Link Systems Inc.","versions":[{"lessThan":"0.20.0 2.0.0 v605f.0 Build 250305 Rel.14728n","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"unaffected","product":"EX220(US1) V1.0","vendor":"TP-Link Systems Inc.","versions":[{"lessThan":"0.20.0 2.0.0 v605f.0 Build 250305 Rel.14728n","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"unaffected","product":"EX222(EU1) V1.0","vendor":"TP-Link Systems Inc.","versions":[{"lessThan":"0.20.0 2.0.0 v605f.0 Build 250305 Rel.14728n","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"unaffected","product":"EX222(KR) V1.0","vendor":"TP-Link Systems Inc.","versions":[{"lessThan":"0.20.0 2.0.0 v609b.0 Build 260427 Rel.16915","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"unaffected","product":"EX222(US1) V1.0","vendor":"TP-Link Systems Inc.","versions":[{"lessThan":"0.20.0 2.0.0 v605f.0 Build 250305 Rel.14728n","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"unaffected","product":"EX511(BR) V2.0/2.8/2.9","vendor":"TP-Link Systems Inc.","versions":[{"lessThan":"0.9.0 3.0.0 v607e.0 Build 260520 Rel.33425n","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"unaffected","product":"EX511(EU1) V2.0","vendor":"TP-Link Systems Inc.","versions":[{"lessThan":"0.9.0 3.0.0 v607e.0 Build 260520 Rel.33425n","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"unaffected","product":"EX511(US1) V2.0","vendor":"TP-Link Systems Inc.","versions":[{"lessThan":"0.8.0 3.0.0 v607e.0 Build 260424 Rel.27419n","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"unaffected","product":"EX520(US1) V1.0","vendor":"TP-Link Systems Inc.","versions":[{"lessThan":"0.7.0 3.0.0 v60b4.0 Build 251229 Rel.84306n","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"unaffected","product":"EX520v(EU1)1.0","vendor":"TP-Link Systems Inc.","versions":[{"lessThan":"0.1.0 3.0.0 v60ee.0 Build 250310 Rel.55637n","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"unaffected","product":"EX521(US1) V1.0","vendor":"TP-Link Systems Inc.","versions":[{"lessThan":"0.3.0 3.0.0 v60e3.0 Build 250925 Rel.66797n","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"unaffected","product":"EX820v(EU1) V1.0","vendor":"TP-Link Systems Inc.","versions":[{"lessThan":"0.4.0 3.1.9 v6087.0 Build 250928 Rel.59674n","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"unaffected","product":"EX920(US2) V1.6/V1.0","vendor":"TP-Link Systems Inc.","versions":[{"lessThan":"0.8.0 3.2.2 v6080.0 Build 260309 Rel.54790n","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"unaffected","product":"XC220-G3v(EU1) V2.30","vendor":"TP-Link Systems Inc.","versions":[{"lessThan":"1.16.0 0.8.0 v6062.0 Build 250817 Rel.23310n","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"unaffected","product":"XC220-G3v(US1) V2.30","vendor":"TP-Link Systems Inc.","versions":[{"lessThan":"1.16.0 0.8.0 v6062.0 Build 250817 Rel.23310n","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"unaffected","product":"XX530v(BR)v1.0","vendor":"TP-Link Systems Inc.","versions":[{"lessThan":"0.6.0 3.0.0 v6096.0 Build 250416 Rel.26048n","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"unaffected","product":"XX530v(BR)v2.0","vendor":"TP-Link Systems Inc.","versions":[{"lessThan":"0.4.0 3.1.10 v60dc.0 Build 250520 Rel.69748n","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"unaffected","product":"XX530v(US1)","vendor":"TP-Link Systems Inc.","versions":[{"lessThan":"0.6.0 3.0.0 v6096.0 Build 250416 Rel.26048n","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"unaffected","product":"XX530v(EU1)","vendor":"TP-Link Systems Inc.","versions":[{"lessThan":"0.3.0 3.1.10 v6107.0 Build 250425 Rel.71973n","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"unaffected","product":"XX230v(BR) V1.0","vendor":"TP-Link Systems Inc.","versions":[{"lessThan":"0.16.0 3.0.0 v6066.0 Build 250423 Rel.43799n","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"unaffected","product":"VX800v(DE) V1.0","vendor":"TP-Link Systems Inc.","versions":[{"lessThan":"800.0.16","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"unaffected","product":"VX1800v(EU1) V1.0","vendor":"TP-Link Systems Inc.","versions":[{"lessThan":"0.14.0 2.0.0 v6092.0 Build 250417 Rel.24761n","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"unaffected","product":"VX420-G2h(AU) V3.0","vendor":"TP-Link Systems Inc.","versions":[{"lessThan":"0.2.0 2.0.0 v60df.0 Build 250427 Rel.38233n","status":"affected","version":"0","versionType":"custom"}]}],"credits":[{"lang":"en","type":"finder","value":"Gerhard Hechenberger, Stefan Schweighofer, Constantin Schieber-Knoebl from the SEC Consult Vulnerability Lab"}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>The affected TP-Link Aginet devices<span>&nbsp;contain a flaw in the web management interface where authentication\nchecks are not consistently enforced on certain endpoints. An attacker can send\nspecially crafted requests to bypass authentication and directly invoke\nprivileged functionality without valid credentials. This issue arises from\nimproper enforcement of access control mechanisms on sensitive operations.</span></p>\n\n<p>Successful\nexploitation may allow an unauthenticated attacker to execute privileged\noperations and gain full control of the device.</p>"}],"value":"The affected TP-Link Aginet devices contain a flaw in the web management interface where authentication\nchecks are not consistently enforced on certain endpoints. An attacker can send\nspecially crafted requests to bypass authentication and directly invoke\nprivileged functionality without valid credentials. This issue arises from\nimproper enforcement of access control mechanisms on sensitive operations.\n\n\n\n\n\nSuccessful\nexploitation may allow an unauthenticated attacker to execute privileged\noperations and gain full control of the device."}],"impacts":[{"capecId":"CAPEC-115","descriptions":[{"lang":"en","value":"CAPEC-115: Authentication Bypass"}]}],"metrics":[{"cvssV4_0":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"ADJACENT","baseScore":8.7,"baseSeverity":"HIGH","exploitMaturity":"NOT_DEFINED","privilegesRequired":"NONE","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnerabilityResponseEffort":"NOT_DEFINED"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-862","description":"CWE-862: Missing Authorization","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-08-10T22:23:41.934Z","orgId":"f23511db-6c3e-4e32-a477-6aa17d310630","shortName":"TPLink"},"references":[{"name":"TP-Link Security Advisory","tags":["vendor-advisory"],"url":"https://www.tp-link.com/us/support/faq/5239/"}],"source":{"discovery":"UNKNOWN"},"title":"Authentication Bypass via Broken Access Control in Web Server in Multiple TP-Link Aginet Devices","x_generator":{"engine":"Vulnogram 1.0.4"}}},"cveMetadata":{"assignerOrgId":"f23511db-6c3e-4e32-a477-6aa17d310630","assignerShortName":"TPLink","cveId":"CVE-2025-30237","datePublished":"2026-08-10T22:23:41.934Z","dateReserved":"2025-03-19T11:09:33.244Z","dateUpdated":"2026-08-11T14:23:49.823Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-08-10 23:16:48","lastModifiedDate":"2026-08-18 15:04:46","problem_types":["CWE-862","CWE-862 CWE-862: Missing Authorization"],"metrics":{"cvssMetricV40":[{"source":"f23511db-6c3e-4e32-a477-6aa17d310630","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"ADJACENT","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-11T14:23:38.414631Z","id":"CVE-2025-30237","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2025","CveId":"30237","Ordinal":"1","Title":"Authentication Bypass via Broken Access Control in Web Server in","CVE":"CVE-2025-30237","Year":"2025"},"notes":[{"CveYear":"2025","CveId":"30237","Ordinal":"1","NoteData":"The affected TP-Link Aginet devices contain a flaw in the web management interface where authentication\nchecks are not consistently enforced on certain endpoints. An attacker can send\nspecially crafted requests to bypass authentication and directly invoke\nprivileged functionality without valid credentials. This issue arises from\nimproper enforcement of access control mechanisms on sensitive operations.\n\n\n\n\n\nSuccessful\nexploitation may allow an unauthenticated attacker to execute privileged\noperations and gain full control of the device.","Type":"Description","Title":"Authentication Bypass via Broken Access Control in Web Server in"}]}}}