Description
Certain web
interface components in affected TP-Link Aginet devices do not validate and sanitize user-supplied input properly before
passing it to system-level command execution functions.  An authenticated adjacent attacker may inject
specially crafted input to execute arbitrary operation system commands with
elevated privileges.









Successful
exploitation may allow execution of arbitrary system commands, potentially
leading to full device compromise.
Published: 2026-08-10
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Certain web interface components on affected TP‑Link Aginet devices lack proper validation and sanitization of user input before it is passed to system‑level command execution functions. An authenticated attacker who is adjacent to the device can craft input that causes arbitrary operating‑system commands to be executed with elevated privileges, allowing total takeover of the device.

Affected Systems

The vulnerability affects a broad range of TP‑Link Systems Inc. Aginet devices. Affected models include EB210 Pro, EB810v, EX220, EX222, EX520v, EX820v, EX920, HB210, HB410, HB610, HB710, HB810, VX420‑G2, VX800v, XX230v, and XX530v, across various regional variants. The impacted firmware versions range from 1.0 up to 1.6 and 2.6 depending on the specific model, as listed by the vendor.

Risk and Exploitability

The CVSS score of 8.6 categorizes this issue as high severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog, but its potential impact remains significant. Exploitation requires local or adjacent access and valid credentials to the web interface; once authenticated, an attacker can inject malicious input and execute arbitrary system commands, leading to full device compromise.

Generated by OpenCVE AI on August 10, 2026 at 23:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the firmware of all affected TP‑Link Aginet devices to the latest version released by the vendor; the patch addresses the command‑injection flaw.
  • If a patch is not yet available for a particular model, disable the web management interface or restrict its accessibility to a trusted internal subnet, preventing unauthenticated users from reaching the vulnerable page.
  • Implement network segmentation and firewall rules that limit the device’s exposure to local network traffic, ensuring that only authorized devices can communicate with it over the management ports.

Generated by OpenCVE AI on August 10, 2026 at 23:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 12 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Tp-link
Tp-link eb210 Pro(eu1) 1.0
Tp-link eb210 Pro(us1) 1.0
Tp-link eb810v(eu1) V1.0
Tp-link ex220(br) V1.0/1.20/1.28/1.29/1.8
Tp-link ex220(br) V2.0
Tp-link ex220(eu1) V1.0/1.20
Tp-link ex220(ru) V1.0
Tp-link ex220(us1) V1.0
Tp-link ex222(eu1) V1.0
Tp-link ex222(kr) V1.0
Tp-link ex222(us1) V1.0
Tp-link ex520v(eu1)1.0
Tp-link ex820v(eu1) V1.0
Tp-link ex920(us2) V1.6/v1.0
Tp-link hb210(eu1) 1.0
Tp-link hb210(us2) 1.0
Tp-link hb210 Pro(eu1)1.0
Tp-link hb210 Pro(us2)1.0/1.6
Tp-link hb410( Eu1) 1.0
Tp-link hb610(ca) V2.0
Tp-link hb610(eu1)
Tp-link hb610(us2) V2.6/2.0
Tp-link hb710(eu1) 1.0
Tp-link hb710(us2) V1.6/1.0
Tp-link hb810(eu1) V2.0
Tp-link hb810(us2) V1.0/1.6/2.0/2.6
Tp-link vx420-g2h(au) V3.0
Tp-link vx800v(de) V1.0
Tp-link xx230v(br) V1.0
Tp-link xx530v(br)v2.0
Tp-link xx530v(eu1)
Vendors & Products Tp-link
Tp-link eb210 Pro(eu1) 1.0
Tp-link eb210 Pro(us1) 1.0
Tp-link eb810v(eu1) V1.0
Tp-link ex220(br) V1.0/1.20/1.28/1.29/1.8
Tp-link ex220(br) V2.0
Tp-link ex220(eu1) V1.0/1.20
Tp-link ex220(ru) V1.0
Tp-link ex220(us1) V1.0
Tp-link ex222(eu1) V1.0
Tp-link ex222(kr) V1.0
Tp-link ex222(us1) V1.0
Tp-link ex520v(eu1)1.0
Tp-link ex820v(eu1) V1.0
Tp-link ex920(us2) V1.6/v1.0
Tp-link hb210(eu1) 1.0
Tp-link hb210(us2) 1.0
Tp-link hb210 Pro(eu1)1.0
Tp-link hb210 Pro(us2)1.0/1.6
Tp-link hb410( Eu1) 1.0
Tp-link hb610(ca) V2.0
Tp-link hb610(eu1)
Tp-link hb610(us2) V2.6/2.0
Tp-link hb710(eu1) 1.0
Tp-link hb710(us2) V1.6/1.0
Tp-link hb810(eu1) V2.0
Tp-link hb810(us2) V1.0/1.6/2.0/2.6
Tp-link vx420-g2h(au) V3.0
Tp-link vx800v(de) V1.0
Tp-link xx230v(br) V1.0
Tp-link xx530v(br)v2.0
Tp-link xx530v(eu1)

Mon, 10 Aug 2026 22:45:00 +0000

Type Values Removed Values Added
Description Certain web interface components in affected TP-Link Aginet devices do not validate and sanitize user-supplied input properly before passing it to system-level command execution functions.  An authenticated adjacent attacker may inject specially crafted input to execute arbitrary operation system commands with elevated privileges. Successful exploitation may allow execution of arbitrary system commands, potentially leading to full device compromise.
Title OS Command Injection in Web Interface in Multiple TP-Link Aginet Devices
Weaknesses CWE-78
References
Metrics cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Tp-link Eb210 Pro(eu1) 1.0 Eb210 Pro(us1) 1.0 Eb810v(eu1) V1.0 Ex220(br) V1.0/1.20/1.28/1.29/1.8 Ex220(br) V2.0 Ex220(eu1) V1.0/1.20 Ex220(ru) V1.0 Ex220(us1) V1.0 Ex222(eu1) V1.0 Ex222(kr) V1.0 Ex222(us1) V1.0 Ex520v(eu1)1.0 Ex820v(eu1) V1.0 Ex920(us2) V1.6/v1.0 Hb210(eu1) 1.0 Hb210(us2) 1.0 Hb210 Pro(eu1)1.0 Hb210 Pro(us2)1.0/1.6 Hb410( Eu1) 1.0 Hb610(ca) V2.0 Hb610(eu1) Hb610(us2) V2.6/2.0 Hb710(eu1) 1.0 Hb710(us2) V1.6/1.0 Hb810(eu1) V2.0 Hb810(us2) V1.0/1.6/2.0/2.6 Vx420-g2h(au) V3.0 Vx800v(de) V1.0 Xx230v(br) V1.0 Xx530v(br)v2.0 Xx530v(eu1)
cve-icon MITRE

Status: PUBLISHED

Assigner: TPLink

Published:

Updated: 2026-08-12T18:56:29.140Z

Reserved: 2025-03-19T11:09:33.245Z

Link: CVE-2025-30241

cve-icon Vulnrichment

Updated: 2026-08-12T18:56:24.821Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-10T23:16:50.670

Modified: 2026-08-18T15:04:46.610

Link: CVE-2025-30241

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-11T14:21:20Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')