Authentication Bypass in TP-Link Aginet Devices
CVE-2025-30237

8.7HIGH

What is CVE-2025-30237?

The TP-Link Aginet devices exhibit a significant flaw within their web management interface due to inconsistent enforcement of authentication checks across certain endpoints. This vulnerability permits an attacker to exploit specially crafted requests, enabling unauthorized access to privileged functions without valid credentials. The root of the issue lies in inadequate enforcement of access control mechanisms concerning sensitive operations, potentially allowing an unauthenticated user to execute commands that compromise the device's integrity and offer full control over it.

Affected Version(s)

EX141(BR) V1.0/1.9 0 < 1.8.0 3.1.0 v608a.0 Build 250425 Rel.40905n

EX141(EU1) V1.0 0 < 1.7.0 3.1.0 v608a.0 Build 250418 Rel.8257n

EX141(US1) V1.0 0 < 1.7.0 3.1.0 v608a.0 Build 250418 Rel.8257n

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Gerhard Hechenberger, Stefan Schweighofer, Constantin Schieber-Knoebl from the SEC Consult Vulnerability Lab
.