The affected TP-Link Aginet devices contain a flaw in the web management interface where authentication
checks are not consistently enforced on certain endpoints. An attacker can send
specially crafted requests to bypass authentication and directly invoke
privileged functionality without valid credentials. This issue arises from
improper enforcement of access control mechanisms on sensitive operations.
Successful
exploitation may allow an unauthenticated attacker to execute privileged
operations and gain full control of the device.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.tp-link.com/us/support/faq/5239/ |
|
History
Mon, 10 Aug 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The affected TP-Link Aginet devices contain a flaw in the web management interface where authentication checks are not consistently enforced on certain endpoints. An attacker can send specially crafted requests to bypass authentication and directly invoke privileged functionality without valid credentials. This issue arises from improper enforcement of access control mechanisms on sensitive operations. Successful exploitation may allow an unauthenticated attacker to execute privileged operations and gain full control of the device. | |
| Title | Authentication Bypass via Broken Access Control in Web Server in Multiple TP-Link Aginet Devices | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: TPLink
Published:
Updated: 2026-08-10T22:23:41.934Z
Reserved: 2025-03-19T11:09:33.244Z
Link: CVE-2025-30237
No data.
No data.
No data.
OpenCVE Enrichment
No data.