{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2025-30241","assignerOrgId":"f23511db-6c3e-4e32-a477-6aa17d310630","state":"PUBLISHED","assignerShortName":"TPLink","dateReserved":"2025-03-19T11:09:33.245Z","datePublished":"2026-08-10T22:26:08.525Z","dateUpdated":"2026-08-12T18:56:29.140Z"},"containers":{"cna":{"providerMetadata":{"orgId":"f23511db-6c3e-4e32-a477-6aa17d310630","shortName":"TPLink","dateUpdated":"2026-08-10T22:26:08.525Z"},"title":"OS Command Injection in Web Interface in Multiple TP-Link Aginet Devices","problemTypes":[{"descriptions":[{"lang":"en","cweId":"CWE-78","description":"CWE-78 Improper neutralization of special elements used in an OS command ('OS command injection')","type":"CWE"}]}],"impacts":[{"capecId":"CAPEC-88","descriptions":[{"lang":"en","value":"CAPEC-88: OS Command Injection"}]}],"affected":[{"vendor":"TP-Link Systems Inc.","product":"HB810(US2) V1.0/1.6/2.0/2.6","versions":[{"status":"affected","version":"0","lessThan":"0.9.0 3.2.2 v6095.0 Build 260717 Rel.67188n","versionType":"custom"}],"defaultStatus":"unaffected"},{"vendor":"TP-Link Systems Inc.","product":"HB810(EU1) V2.0","versions":[{"status":"affected","version":"0","lessThan":"0.10.0 3.2.2 v6095.0 Build 260306 Rel.47567n","versionType":"custom"}],"defaultStatus":"unaffected"},{"vendor":"TP-Link Systems Inc.","product":"HB710(US2) V1.6/1.0","versions":[{"status":"affected","version":"0","lessThan":"0.3.0 3.0.0 v60be.0 Build 251128 Rel.43956n","versionType":"custom"}],"defaultStatus":"unaffected"},{"vendor":"TP-Link Systems Inc.","product":"HB710(EU1) 1.0","versions":[{"status":"affected","version":"0","lessThan":"0.3.0 3.0.0 v60be.0 Build 251128 Rel.43956n","versionType":"custom"}],"defaultStatus":"unaffected"},{"vendor":"TP-Link Systems Inc.","product":"HB610(US2) V2.6/2.0","versions":[{"status":"affected","version":"0","lessThan":"0.6.0 3.0.0 v60af.0 Build 251204 Rel.20362n","versionType":"custom"}],"defaultStatus":"unaffected"},{"vendor":"TP-Link Systems Inc.","product":"HB610(EU1)","versions":[{"status":"affected","version":"0","lessThan":"0.6.0 3.0.0 v60af.0 Build 251204 Rel.20362n","versionType":"custom"}],"defaultStatus":"unaffected"},{"vendor":"TP-Link Systems Inc.","product":"HB610(CA) V2.0","versions":[{"status":"affected","version":"0","lessThan":"0.6.0 3.0.0 v60af.0 Build 251216 Rel.46954n","versionType":"custom"}],"defaultStatus":"unaffected"},{"vendor":"TP-Link Systems Inc.","product":"HB410( EU1) 1.0","versions":[{"status":"affected","version":"0","lessThan":"0.3.0 3.0.0 v60bf.0 Build 250901 Rel.45574n","versionType":"custom"}],"defaultStatus":"unaffected"},{"vendor":"TP-Link Systems Inc.","product":"HB210(US2) 1.0","versions":[{"status":"affected","version":"0","lessThan":"0.2.0 3.0.0 v60f9.0 Build 250826 Rel.47715n","versionType":"custom"}],"defaultStatus":"unaffected"},{"vendor":"TP-Link Systems Inc.","product":"HB210(EU1) 1.0","versions":[{"status":"affected","version":"0","lessThan":"0.2.0 3.0.0 v60f9.0 Build 250826 Rel.47715n","versionType":"custom"}],"defaultStatus":"unaffected"},{"vendor":"TP-Link Systems Inc.","product":"HB210 Pro(EU1)1.0","versions":[{"status":"affected","version":"0","lessThan":"0.5.0 3.0.0 v60d5.0 Build 250922 Rel.13742n","versionType":"custom"}],"defaultStatus":"unaffected"},{"vendor":"TP-Link Systems Inc.","product":"HB210 Pro(US2)1.0/1.6","versions":[{"status":"affected","version":"0","lessThan":"0.8.0 3.0.0 v60d5.0 Build 260318 Rel.78363n","versionType":"custom"}],"defaultStatus":"unaffected"},{"vendor":"TP-Link Systems Inc.","product":"EB210 Pro(EU1) 1.0","versions":[{"status":"affected","version":"0","lessThan":"0.2.0 3.0.0 v60f4.0 Build 250807 Rel.58901n","versionType":"custom"}],"defaultStatus":"unaffected"},{"vendor":"TP-Link Systems Inc.","product":"EB210 Pro(US1) 1.0","versions":[{"status":"affected","version":"0","lessThan":"0.2.0 3.0.0 v60f4.0 Build 250807 Rel.58901n","versionType":"custom"}],"defaultStatus":"unaffected"},{"vendor":"TP-Link Systems Inc.","product":"EB810v(EU1) V1.0","versions":[{"status":"affected","version":"0","lessThan":"0.6.0 3.0.0 v608b.0 Build 250613 Rel.10497n","versionType":"custom"}],"defaultStatus":"unaffected"},{"vendor":"TP-Link Systems Inc.","product":"EX220(BR) V1.0/1.20/1.28/1.29/1.8","versions":[{"status":"affected","version":"0","lessThan":"0.20.0 2.0.0 v605f.0 Build 250305 Rel.14728n","versionType":"custom"}],"defaultStatus":"unaffected"},{"vendor":"TP-Link Systems Inc.","product":"EX220(BR) V2.0","versions":[{"status":"affected","version":"0","lessThan":"0.19.0 2.0.0 v609b.0 Build 250814 Rel.49732n","versionType":"custom"}],"defaultStatus":"unaffected"},{"vendor":"TP-Link Systems Inc.","product":"EX220(EU1) V1.0/1.20","versions":[{"status":"affected","version":"0","lessThan":"0.20.0 2.0.0 v605f.0 Build 250305 Rel.14728n","versionType":"custom"}],"defaultStatus":"unaffected"},{"vendor":"TP-Link Systems Inc.","product":"EX220(RU) V1.0","versions":[{"status":"affected","version":"0","lessThan":"0.20.0 2.0.0 v605f.0 Build 250305 Rel.14728n","versionType":"custom"}],"defaultStatus":"unaffected"},{"vendor":"TP-Link Systems Inc.","product":"EX220(US1) V1.0","versions":[{"status":"affected","version":"0","lessThan":"0.20.0 2.0.0 v605f.0 Build 250305 Rel.14728n","versionType":"custom"}],"defaultStatus":"unaffected"},{"vendor":"TP-Link Systems Inc.","product":"EX222(EU1) V1.0","versions":[{"status":"affected","version":"0","lessThan":"0.20.0 2.0.0 v605f.0 Build 250305 Rel.14728n","versionType":"custom"}],"defaultStatus":"unaffected"},{"vendor":"TP-Link Systems Inc.","product":"EX222(KR) V1.0","versions":[{"status":"affected","version":"0","lessThan":"0.20.0 2.0.0 v609b.0 Build 260427 Rel.16915","versionType":"custom"}],"defaultStatus":"unaffected"},{"vendor":"TP-Link Systems Inc.","product":"EX222(US1) V1.0","versions":[{"status":"affected","version":"0","lessThan":"0.20.0 2.0.0 v605f.0 Build 250305 Rel.14728n","versionType":"custom"}],"defaultStatus":"unaffected"},{"vendor":"TP-Link Systems Inc.","product":"EX520v(EU1)1.0","versions":[{"status":"affected","version":"0","lessThan":"0.1.0 3.0.0 v60ee.0 Build 250310 Rel.55637n","versionType":"custom"}],"defaultStatus":"unaffected"},{"vendor":"TP-Link Systems Inc.","product":"EX820v(EU1) V1.0","versions":[{"status":"affected","version":"0","lessThan":"0.4.0 3.1.9 v6087.0 Build 250928 Rel.59674n","versionType":"custom"}],"defaultStatus":"unaffected"},{"vendor":"TP-Link Systems Inc.","product":"EX920(US2) V1.6/V1.0","versions":[{"status":"affected","version":"0","lessThan":"0.8.0 3.2.2 v6080.0 Build 260309 Rel.54790n","versionType":"custom"}],"defaultStatus":"unaffected"},{"vendor":"TP-Link Systems Inc.","product":"XX530v(BR)v2.0","versions":[{"status":"affected","version":"0","lessThan":"0.4.0 3.1.10 v60dc.0 Build 250520 Rel.69748n","versionType":"custom"}],"defaultStatus":"unaffected"},{"vendor":"TP-Link Systems Inc.","product":"XX530v(EU1)","versions":[{"status":"affected","version":"0","lessThan":"0.3.0 3.1.10 v6107.0 Build 250425 Rel.71973n","versionType":"custom"}],"defaultStatus":"unaffected"},{"vendor":"TP-Link Systems Inc.","product":"XX230v(BR) V1.0","versions":[{"status":"affected","version":"0","lessThan":"0.16.0 3.0.0 v6066.0 Build 250423 Rel.43799n","versionType":"custom"}],"defaultStatus":"unaffected"},{"vendor":"TP-Link Systems Inc.","product":"VX800v(DE) V1.0","versions":[{"status":"affected","version":"0","lessThan":"800.0.16","versionType":"custom"}],"defaultStatus":"unaffected"},{"vendor":"TP-Link Systems Inc.","product":"VX420-G2h(AU) V3.0","versions":[{"status":"affected","version":"0","lessThan":"0.2.0 2.0.0 v60df.0 Build 250427 Rel.38233n","versionType":"custom"}],"defaultStatus":"unaffected"}],"descriptions":[{"lang":"en","value":"Certain web\ninterface components in affected TP-Link Aginet devices do not validate and sanitize user-supplied input properly before\npassing it to system-level command execution functions.  An authenticated adjacent attacker may inject\nspecially crafted input to execute arbitrary operation system commands with\nelevated privileges.\n\n\n\n\n\n\n\n\n\nSuccessful\nexploitation may allow execution of arbitrary system commands, potentially\nleading to full device compromise.","supportingMedia":[{"type":"text/html","base64":false,"value":"<p>Certain web\ninterface components in affected TP-Link Aginet devices do not validate and sanitize user-supplied input properly before\npassing it to system-level command execution functions.&nbsp; An authenticated adjacent attacker may inject\nspecially crafted input to execute arbitrary operation system commands with\nelevated privileges.</p><p>\n\n</p><p>Successful\nexploitation may allow execution of arbitrary system commands, potentially\nleading to full device compromise.</p>"}]}],"references":[{"url":"https://www.tp-link.com/us/support/faq/5239/","name":"TP-Link Security Advisory","tags":["vendor-advisory"]}],"metrics":[{"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}],"cvssV4_0":{"attackVector":"ADJACENT","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","subConfidentialityImpact":"NONE","vulnIntegrityImpact":"HIGH","subIntegrityImpact":"NONE","vulnAvailabilityImpact":"HIGH","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED","version":"4.0","baseSeverity":"HIGH","baseScore":8.6,"vectorString":"CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}}],"credits":[{"lang":"en","value":"Gerhard Hechenberger, Stefan Schweighofer, Constantin Schieber-Knoebl from the SEC Consult Vulnerability Lab","type":"finder"}],"source":{"discovery":"UNKNOWN"},"x_generator":{"engine":"Vulnogram 1.0.4"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-08-12T18:55:44.663742Z","id":"CVE-2025-30241","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-08-12T18:56:29.140Z"}}]}}