CVE-2025-30241
8.6TP-Link · Aginet HB810, HB710, HB610
TP-Link Aginet devices are susceptible to OS command injection due to improper input validation in web interface components.
Executive summary
A critical OS command injection vulnerability in TP-Link Aginet devices allows authenticated users to execute arbitrary system-level commands.
Vulnerability
The web interface fails to sanitize user-supplied input before passing it to system-level command execution functions (CWE-78). This allows an authenticated attacker to inject malicious commands into the underlying operating system.
Business impact
Successful exploitation grants an attacker the ability to execute arbitrary commands with system-level privileges, leading to full device compromise. This poses a severe threat to data confidentiality and network integrity, consistent with the high CVSS score of 8.6, and could facilitate further lateral movement into the connected network.
Remediation
Immediate Action: Apply the latest firmware updates released by TP-Link to patch the vulnerable web interface components.
Proactive Monitoring: Inspect system logs for unusual command execution patterns or unauthorized modifications to system configuration files.
Compensating Controls: Implement a Web Application Firewall (WAF) or equivalent inspection mechanism to block malicious input patterns directed at the device management interface.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Command injection is a high-risk vulnerability that can lead to complete system takeover. Organizations using these TP-Link devices must treat the vendor firmware patch as a critical update and deploy it immediately to prevent potential remote code execution.