TP-Link has disclosed multiple high-severity vulnerabilities affecting ISP-managed Aginet networking products, including mesh systems, routers, PON devices, and xDSL modems.
The flaws could allow attackers with network access to bypass authentication, escalate privileges, steal sensitive information, read device files, and execute operating system commands.
The security advisory, last updated on August 10, 2026, tracks the issues as CVE-2025-30237 through CVE-2025-30241. The affected products are commonly supplied, configured, and updated by internet service providers, meaning firmware availability may vary by operator and region.
The most serious flaw, CVE-2025-30237, is an authentication bypass vulnerability in the web management interface. It has a CVSS v4 score of 8.7 and results from broken access control on certain endpoints.
An attacker on an adjacent network may send specially crafted requests to reach privileged functions without providing valid credentials. If exploited, the issue could give an unauthenticated attacker full control of the affected device.
Multiple TP-Link Vulnerabilities
CVE-2025-30238, rated 8.6, is an improper authorization flaw in user-management functions. A low-privileged authenticated user may be able to perform administrator-level actions, including creating privileged accounts or changing critical device settings. This could allow an attacker with limited access to expand their control over a router or mesh node.
Another high-severity issue, CVE-2025-30239, involves hardcoded cryptographic keys stored in firmware. The vulnerability has a CVSS score of 8.5.
An attacker with access to the device’s storage could recover the embedded keys and decrypt protected configuration data. Exposed information may include credentials and ISP-related service settings, creating a risk of further compromise.
CVE-2025-30240 is a medium-severity arbitrary file-read issue with a CVSS score of 5.1. The flaw affects the USB HTTPS access path and stems from improper handling of symbolic links on external USB storage.
A person with physical access to the device may create a malicious symbolic link on a supported medium and use it to access sensitive files in the router filesystem.
| CVE | Vulnerability | Severity |
|---|---|---|
| CVE-2025-30237 | Authentication bypass | High |
| CVE-2025-30238 | Privilege escalation | High |
| CVE-2025-30239 | Sensitive data exposure | High |
| CVE-2025-30240 | Arbitrary file read | Medium |
| CVE-2025-30241 | OS command injection | High |
The final issue, CVE-2025-30241, is an OS command injection vulnerability with a severity rating of 8.6. It exists because some web-interface components fail to properly validate user-controlled input before passing it to system-level command functions.
An authenticated attacker on the local network could inject commands and execute them with elevated privileges, potentially taking complete control of the device. Affected hardware includes models from TP-Link’s HB, HX, HC, EB, EC, EX, XC, XX, and VX series.
Examples include HB810, HB710, EX220, EX222, EX920, EC220-G5, XX530v, and VX1800v variants. The exact impact depends on the regional model, hardware version, ISP customizations, and installed firmware.
TP-Link said remediation for ISP-managed devices will be coordinated through service providers. In many cases, updates may be installed automatically through ISP management platforms.
Users should check the router administration interface or the provider’s management application for firmware updates. If an update is unavailable, customers should contact their ISP to confirm whether their device is affected and when a patched firmware release will be deployed.
Because several flaws require local or adjacent-network access, users should also restrict exposure of management interfaces, use strong, unique administrator credentials, turn off unnecessary remote management features, and keep untrusted users off the local network.
Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.

