CVE-2025-30238: TP-Link Systems Inc EB210 PROEU1 1.0
High severity, CVSS 8.6. EPSS: 0.2% chance of exploitation in the next 30 days.
In affected TP-Link Aginet devices, insufficient authorization validation allows authenticated low-privileged users to execute higher-privileged operations. An attacker may perform administrative actions such as creating privileged accounts or modifying critical configuration settings.
Affected products
- TP-Link Systems Inc EB210 PROEU1 1.0
- TP-Link Systems Inc EB210 PROUS1 1.0
- TP-Link Systems Inc EB810VEU1 v1.0
- TP-Link Systems Inc EX141BR v1.0/1.9
- TP-Link Systems Inc EX141EU1 v1.0
- TP-Link Systems Inc EX141US1 v1.0
- TP-Link Systems Inc EX220BR v1.0/1.20/1.28/1.29/1.8
- TP-Link Systems Inc EX220BR v2.0
- TP-Link Systems Inc EX220EU1 v1.0/1.20
- TP-Link Systems Inc EX220RU v1.0
- TP-Link Systems Inc EX220US1 v1.0
- TP-Link Systems Inc EX222EU1 v1.0
- TP-Link Systems Inc EX222KR v1.0
- TP-Link Systems Inc EX222US1 v1.0
- TP-Link Systems Inc EX511BR v2.0/2.8/2.9
- TP-Link Systems Inc EX511EU1 v2.0
- TP-Link Systems Inc EX511US1 v2.0
- TP-Link Systems Inc EX520US1 v1.0
- TP-Link Systems Inc EX520VEU11.0
- TP-Link Systems Inc EX521US1 v1.0
- TP-Link Systems Inc EX820VEU1 v1.0
- TP-Link Systems Inc EX920US2 v1.6/v1.0
- TP-Link Systems Inc HB210 PROEU11.0
- TP-Link Systems Inc HB210 PROUS21.0/1.6
- TP-Link Systems Inc HB210EU1 1.0
- and 34 more
Published 2026-08-10. Last modified 2026-10-09.