CVE-2025-30237: TP-Link Systems Inc EX141BR v1.0/1.9
High severity, CVSS 8.7. EPSS: 0.3% chance of exploitation in the next 30 days.
The affected TP-Link Aginet devices contain a flaw in the web management interface where authentication checks are not consistently enforced on certain endpoints. An attacker can send specially crafted requests to bypass authentication and directly invoke privileged functionality without valid credentials. This issue arises from improper enforcement of access control mechanisms on sensitive operations. Successful exploitation may allow an unauthenticated attacker to execute privileged operations and gain full control of the device.
Affected products
- TP-Link Systems Inc EX141BR v1.0/1.9
- TP-Link Systems Inc EX141EU1 v1.0
- TP-Link Systems Inc EX141US1 v1.0
- TP-Link Systems Inc EX220BR v1.0/1.20/1.28/1.29/1.8
- TP-Link Systems Inc EX220BR v2.0
- TP-Link Systems Inc EX220EU1 v1.0/1.20
- TP-Link Systems Inc EX220RU v1.0
- TP-Link Systems Inc EX220US1 v1.0
- TP-Link Systems Inc EX222EU1 v1.0
- TP-Link Systems Inc EX222KR v1.0
- TP-Link Systems Inc EX222US1 v1.0
- TP-Link Systems Inc EX511BR v2.0/2.8/2.9
- TP-Link Systems Inc EX511EU1 v2.0
- TP-Link Systems Inc EX511US1 v2.0
- TP-Link Systems Inc EX520US1 v1.0
- TP-Link Systems Inc EX520VEU11.0
- TP-Link Systems Inc EX521US1 v1.0
- TP-Link Systems Inc EX820VEU1 v1.0
- TP-Link Systems Inc EX920US2 v1.6/v1.0
- TP-Link Systems Inc HB210 PROEU11.0
- TP-Link Systems Inc HB210 PROUS21.0/1.6
- TP-Link Systems Inc HB210EU1 1.0
- TP-Link Systems Inc HB210US2 1.0
- TP-Link Systems Inc HB410 EU1 1.0
- TP-Link Systems Inc HB610CA v2.0
- and 31 more
Published 2026-08-10. Last modified 2026-10-09.