Impact
In affected TP‑Link Aginet devices, insufficient authorization validation allows an authenticated low‑privileged user to execute higher privileged operations. This flaw can enable the attacker to create privileged user accounts or alter critical configuration settings, effectively taking full administrative control over the device. The vulnerability results in a complete compromise of confidentiality, integrity and availability of the network resources that rely on the device. The weakness corresponds to improper authorization (CWE‑863).
Affected Systems
Affected TP‑Link devices include EB210 Pro (EU1 and US1) versions 1.0, EB810v EU1 V1.0, EX141 variants BR, EU1 and US1 in versions 1.0 and 1.9, EX220 variants BR (1.0, 1.20, 1.28, 1.29, 1.8), EX220 BR V2.0, EX220 EU1 (1.0, 1.20), EX220 RU and US1 V1.0, EX222 EU1, KR and US1 V1.0, EX511 BR (2.0, 2.8, 2.9), EX511 EU1 and US1 V2.0, EX520 US1 V1.0, EX520v EU1 V1.0, EX521 US1 V1.0, EX820v EU1 V1.0, EX920 US2 V1.6 and V1.0, HB210 Pro EU1 and US2 (1.0, 1.6), HB210 EU1 and US2 V1.0, HB410 EU1 V1.0, HB610 CA V2.0, HB610 EU1, HB610 US2 V2.6 and V2.0, HB710 EU1 and US2 (1.0, 1.6), HB810 EU1 V2.0 and US2 (1.0, 1.6, 2.0, 2.6), HC220‑G5 BR V1.30, HC220‑G5 EU1 (1.20, 1.0), HC220‑G5 US1 V1.0 and 1.6, HX141 EU1 V1.0, HX220 AU, CA and EU1 V1.0, HX220 US1 V1.0, HX510 AU, CA, EU1 and US1 versions 1.0/2.0 and US2 V2.6, HX710 Pro EU1 V1.0, HX710 EU1 V1.0, VX1800v EU1 V1.0, VX420‑G2h AU V3.0, VX800v DE V1.0, XC220‑G3v EU1 and US1 V2.30, XX230v BR V1.0, XX530v BR and EU1 and US1 V1.0/2.0.
Risk and Exploitability
The CVSS score of 8.6 denotes high severity. While the EPSS score is not provided, the lack of a KEV listing suggests that no widespread exploitation has been reported yet; however, the vulnerability can still be leveraged once authentication is achieved. Information from the description indicates that the flaw requires an existing authenticated low‑privileged user, implying that attackers can compromise accounts that are reachable over the network or by local access to the device. Once the vulnerability is exploited, the attacker can perform administrative actions such as creating privileged accounts or changing configuration settings, leading to a full compromise of the device. Therefore, the risk is significant for any network that relies on these devices and that lacks hardening or network segmentation.
OpenCVE Enrichment