Impact
Certain web interface components on affected TP‑Link Aginet devices lack proper validation and sanitization of user input before it is passed to system‑level command execution functions. An authenticated attacker who is adjacent to the device can craft input that causes arbitrary operating‑system commands to be executed with elevated privileges, allowing total takeover of the device.
Affected Systems
The vulnerability affects a broad range of TP‑Link Systems Inc. Aginet devices. Affected models include EB210 Pro, EB810v, EX220, EX222, EX520v, EX820v, EX920, HB210, HB410, HB610, HB710, HB810, VX420‑G2, VX800v, XX230v, and XX530v, across various regional variants. The impacted firmware versions range from 1.0 up to 1.6 and 2.6 depending on the specific model, as listed by the vendor.
Risk and Exploitability
The CVSS score of 8.6 categorizes this issue as high severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog, but its potential impact remains significant. Exploitation requires local or adjacent access and valid credentials to the web interface; once authenticated, an attacker can inject malicious input and execute arbitrary system commands, leading to full device compromise.
OpenCVE Enrichment