Description
In affected TP-Link Aginet devices, insufficient
authorization validation allows authenticated low-privileged users to execute higher-privileged
operations.





An attacker
may perform administrative actions such as creating privileged accounts or
modifying critical configuration settings.
Published: 2026-08-10
Score: 8.6 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

In affected TP‑Link Aginet devices, insufficient authorization validation allows an authenticated low‑privileged user to execute higher privileged operations. This flaw can enable the attacker to create privileged user accounts or alter critical configuration settings, effectively taking full administrative control over the device. The vulnerability results in a complete compromise of confidentiality, integrity and availability of the network resources that rely on the device. The weakness corresponds to improper authorization (CWE‑863).

Affected Systems

Affected TP‑Link devices include EB210 Pro (EU1 and US1) versions 1.0, EB810v EU1 V1.0, EX141 variants BR, EU1 and US1 in versions 1.0 and 1.9, EX220 variants BR (1.0, 1.20, 1.28, 1.29, 1.8), EX220 BR V2.0, EX220 EU1 (1.0, 1.20), EX220 RU and US1 V1.0, EX222 EU1, KR and US1 V1.0, EX511 BR (2.0, 2.8, 2.9), EX511 EU1 and US1 V2.0, EX520 US1 V1.0, EX520v EU1 V1.0, EX521 US1 V1.0, EX820v EU1 V1.0, EX920 US2 V1.6 and V1.0, HB210 Pro EU1 and US2 (1.0, 1.6), HB210 EU1 and US2 V1.0, HB410 EU1 V1.0, HB610 CA V2.0, HB610 EU1, HB610 US2 V2.6 and V2.0, HB710 EU1 and US2 (1.0, 1.6), HB810 EU1 V2.0 and US2 (1.0, 1.6, 2.0, 2.6), HC220‑G5 BR V1.30, HC220‑G5 EU1 (1.20, 1.0), HC220‑G5 US1 V1.0 and 1.6, HX141 EU1 V1.0, HX220 AU, CA and EU1 V1.0, HX220 US1 V1.0, HX510 AU, CA, EU1 and US1 versions 1.0/2.0 and US2 V2.6, HX710 Pro EU1 V1.0, HX710 EU1 V1.0, VX1800v EU1 V1.0, VX420‑G2h AU V3.0, VX800v DE V1.0, XC220‑G3v EU1 and US1 V2.30, XX230v BR V1.0, XX530v BR and EU1 and US1 V1.0/2.0.

Risk and Exploitability

The CVSS score of 8.6 denotes high severity. While the EPSS score is not provided, the lack of a KEV listing suggests that no widespread exploitation has been reported yet; however, the vulnerability can still be leveraged once authentication is achieved. Information from the description indicates that the flaw requires an existing authenticated low‑privileged user, implying that attackers can compromise accounts that are reachable over the network or by local access to the device. Once the vulnerability is exploited, the attacker can perform administrative actions such as creating privileged accounts or changing configuration settings, leading to a full compromise of the device. Therefore, the risk is significant for any network that relies on these devices and that lacks hardening or network segmentation.

Generated by OpenCVE AI on August 10, 2026 at 23:16 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware update from TP‑Link that resolves the authorization flaw.
  • Restrict management access to trusted internal networks and disable unused remote management interfaces.
  • Enforce strong, unique credentials for all local and remote accounts and change any default passwords.

Generated by OpenCVE AI on August 10, 2026 at 23:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 10 Aug 2026 22:45:00 +0000

Type Values Removed Values Added
Description In affected TP-Link Aginet devices, insufficient authorization validation allows authenticated low-privileged users to execute higher-privileged operations. An attacker may perform administrative actions such as creating privileged accounts or modifying critical configuration settings.
Title Privilege Escalation via Improper Authorization in User Management in multiple TP-Link Aginet Devices
Weaknesses CWE-863
References
Metrics cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: TPLink

Published:

Updated: 2026-08-10T22:24:20.322Z

Reserved: 2025-03-19T11:09:33.244Z

Link: CVE-2025-30238

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-10T23:30:07Z

Weaknesses