Impact
The flaw allows an attacker to bypass authentication checks on certain web interface endpoints and invoke privileged operations without valid credentials, giving full control of the device. The vulnerability arises from improper enforcement of access control mechanisms on sensitive operations, which can lead to compromise of confidentiality, integrity, and availability.
Affected Systems
The vulnerability affects a wide range of TP‑Link Aginet devices. Specific models include EX141 (BR/EU1/US1) v1.0–v1.9, EX220 (BR/EU1) v1.0–v1.20/1.28/1.29/1.8/2.0, EX222 (EU1/KR/US1) v1.0, EX511 (BR/EU1/US1) v2.0–v2.9, EX520 (US1) v1.0, EX521 (US1) v1.0, EX820v (EU1) v1.0, EX920 (US2) v1.0–v1.6, HB210 (EU1/US2) v1.0–v1.6, HB410 (EU1) v1.0, HB610 (CA/EU1/US2) v2.0–v2.6, HB710 (EU1/US2) v1.0–v1.6, HB810 (EU1/US2) v1.0–v2.6, HC220‑G5 (BR/EU1/US1) v1.0–v1.30, HX141 (EU1) v1.0, HX220 (AU/CA/EU1/US1) v1.0, HX510 (AU/CA/EU1/US1/US2) v1.0–v2.6, HX710 (EU1) v1.0, VX1800v (EU1) v1.0, VX420‑G2h (AU) v3.0, VX800v (DE) v1.0, XC220‑G3v (EU1/US1) v2.30, XX230v (BR) v1.0, XX530v (BR/US1/EU1) v1.0–v2.0.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity vulnerability that can lead to full device compromise. Because the attack vector is remote through the web management interface and no authentication is required, the EPSS score is not available but the absence of a KEV listing suggests that public exploitation may not yet be widespread; however, the risk remains high. The flaw directly bypasses authorization controls (CWE‑862), allowing unauthenticated users to invoke privileged operations that affect confidentiality, integrity, and availability of the device.
OpenCVE Enrichment