CVE-2025-30241: TP-Link Systems Inc EB210 PROEU1 1.0
High severity, CVSS 8.6. EPSS: 0.4% chance of exploitation in the next 30 days.
Certain web interface components in affected TP-Link Aginet devices do not validate and sanitize user-supplied input properly before passing it to system-level command execution functions. An authenticated adjacent attacker may inject specially crafted input to execute arbitrary operation system commands with elevated privileges. Successful exploitation may allow execution of arbitrary system commands, potentially leading to full device compromise.
Affected products
- TP-Link Systems Inc EB210 PROEU1 1.0
- TP-Link Systems Inc EB210 PROUS1 1.0
- TP-Link Systems Inc EB810VEU1 v1.0
- TP-Link Systems Inc EX220BR v1.0/1.20/1.28/1.29/1.8
- TP-Link Systems Inc EX220BR v2.0
- TP-Link Systems Inc EX220EU1 v1.0/1.20
- TP-Link Systems Inc EX220RU v1.0
- TP-Link Systems Inc EX220US1 v1.0
- TP-Link Systems Inc EX222EU1 v1.0
- TP-Link Systems Inc EX222KR v1.0
- TP-Link Systems Inc EX222US1 v1.0
- TP-Link Systems Inc EX520VEU11.0
- TP-Link Systems Inc EX820VEU1 v1.0
- TP-Link Systems Inc EX920US2 v1.6/v1.0
- TP-Link Systems Inc HB210 PROEU11.0
- TP-Link Systems Inc HB210 PROUS21.0/1.6
- TP-Link Systems Inc HB210EU1 1.0
- TP-Link Systems Inc HB210US2 1.0
- TP-Link Systems Inc HB410 EU1 1.0
- TP-Link Systems Inc HB610CA v2.0
- TP-Link Systems Inc HB610EU1
- TP-Link Systems Inc HB610US2 v2.6/2.0
- TP-Link Systems Inc HB710EU1 1.0
- TP-Link Systems Inc HB710US2 v1.6/1.0
- TP-Link Systems Inc HB810EU1 v2.0
- and 6 more
Published 2026-08-10. Last modified 2026-09-29.