Description
Certain web
interface components in affected TP-Link Aginet devices do not validate and sanitize user-supplied input properly before
passing it to system-level command execution functions.  An authenticated adjacent attacker may inject
specially crafted input to execute arbitrary operation system commands with
elevated privileges.









Successful
exploitation may allow execution of arbitrary system commands, potentially
leading to full device compromise.
Published: 2026-08-10
Score: 8.6 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Certain web interface components on affected TP‑Link Aginet devices lack proper validation and sanitization of user input before it is passed to system‑level command execution functions. An authenticated attacker who is adjacent to the device can craft input that causes arbitrary operating‑system commands to be executed with elevated privileges, allowing total takeover of the device.

Affected Systems

The vulnerability affects a broad range of TP‑Link Systems Inc. Aginet devices. Affected models include EB210 Pro, EB810v, EX220, EX222, EX520v, EX820v, EX920, HB210, HB410, HB610, HB710, HB810, VX420‑G2, VX800v, XX230v, and XX530v, across various regional variants. The impacted firmware versions range from 1.0 up to 1.6 and 2.6 depending on the specific model, as listed by the vendor.

Risk and Exploitability

The CVSS score of 8.6 categorizes this issue as high severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog, but its potential impact remains significant. Exploitation requires local or adjacent access and valid credentials to the web interface; once authenticated, an attacker can inject malicious input and execute arbitrary system commands, leading to full device compromise.

Generated by OpenCVE AI on August 10, 2026 at 23:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the firmware of all affected TP‑Link Aginet devices to the latest version released by the vendor; the patch addresses the command‑injection flaw.
  • If a patch is not yet available for a particular model, disable the web management interface or restrict its accessibility to a trusted internal subnet, preventing unauthenticated users from reaching the vulnerable page.
  • Implement network segmentation and firewall rules that limit the device’s exposure to local network traffic, ensuring that only authorized devices can communicate with it over the management ports.

Generated by OpenCVE AI on August 10, 2026 at 23:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 10 Aug 2026 22:45:00 +0000

Type Values Removed Values Added
Description Certain web interface components in affected TP-Link Aginet devices do not validate and sanitize user-supplied input properly before passing it to system-level command execution functions.  An authenticated adjacent attacker may inject specially crafted input to execute arbitrary operation system commands with elevated privileges. Successful exploitation may allow execution of arbitrary system commands, potentially leading to full device compromise.
Title OS Command Injection in Web Interface in Multiple TP-Link Aginet Devices
Weaknesses CWE-78
References
Metrics cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: TPLink

Published:

Updated: 2026-08-10T22:26:08.525Z

Reserved: 2025-03-19T11:09:33.245Z

Link: CVE-2025-30241

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-10T23:30:07Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')