CVE-2025-30237

8.7

TP-Link · Aginet devices

TP-Link Aginet devices contain a flaw in the web management interface where authentication checks are not consistently enforced, allowing unauthenticated access.

Executive summary

A critical authentication bypass vulnerability in TP-Link Aginet devices allows unauthenticated attackers to gain administrative control over the web management interface.

Vulnerability

This is a missing authorization vulnerability (CWE-862) occurring within the web management interface. An unauthenticated attacker can access sensitive endpoints without providing valid credentials, effectively bypassing the device's primary security barrier.

Business impact

The CVSS score of 8.7 highlights the severity of this issue, as it permits full administrative control over network infrastructure devices. Unauthorized access to these devices can result in total network compromise, allowing an attacker to intercept traffic, modify configurations, or pivot into the internal network, causing significant operational and security risks.

Remediation

Immediate Action: Identify if your device firmware version matches the affected range and apply the latest security update from the TP-Link support website.

Proactive Monitoring: Audit network management traffic for connections to the web interface from unauthorized or unexpected IP addresses.

Compensating Controls: Disable remote management of the web interface from the WAN side and restrict access to the management console to a dedicated, secure management VLAN.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given that this vulnerability affects network hardware, the risk of lateral movement is extremely high. Device administrators must prioritize updating firmware to the latest version immediately and ensure that these devices are not exposed directly to the public internet.

More TP-Link CVEs