Security Advisory: Multiple Vulnerabilities in ISP-Managed TP-Link Networking Products (CVE-2025-30237 to CVE-2025-30241)
Overview
Multiple security vulnerabilities have been identified in TP-Link Aginet networking products. These issues arise from improper authorization enforcement, insecure handling of sensitive data, unsafe symbolic link processing, and insufficient input validation.
Exploitation of these vulnerabilities requires network access, and in some cases, valid user-credentials to the device management interface.
Description of Vulnerabilities and Impacts:
CVE-2025-30237: Authentication Bypass via Broken Access Control in Web Server
The affected devices contain a flaw in the web management interface where authentication checks are not consistently enforced on certain endpoints. An attacker can send specially crafted requests to bypass authentication and directly invoke privileged functionality without valid credentials. This issue arises from improper enforcement of access control mechanisms on sensitive operations.
Successful exploitation may allow an unauthenticated attacker to execute privileged operations and gain full control of the device.
CVSS v4.0 Score: 8.7 / High
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVE-2025-30238: Privilege Escalation via Improper Authorization in User Management
Insufficient authorization validation allows authenticated low-privileged users to execute higher-privileged operations.
An attacker may perform administrative actions such as creating privileged accounts or modifying critical configuration settings.
CVSS v4.0 Score: 8.6 / High
CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVE-2025-30239: Sensitive Data Exposure due to Hardcoded Cryptographic Keys
Use of hardcoded cryptographic keys embedded in the firmware to protect sensitive configuration data may allow an attacker who has access to device storage to recover the keys and decrypt stored data.
Successful exploitation may allow access to decrypted sensitive configuration data, including credentials and service-related information.
CVSS v4.0 Score: 8.5 / High
CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
CVE-2025-30240: Arbitrary File Read via Improper Symlink Handling in USB HTTPS Access Path
The affected devices do not properly validate symbolic links created on external USB storage devices. By placing a crafted symbolic link on supported storage media, an attacker may cause the system to resolve the link.
Successful exploitation may allow unauthorized read access to sensitive files within the device filesystem.
CVSS v4.0 Score: 5.1 / Medium
CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CVE-2025-30241: OS Command Injection in Web Interface
Certain web interface components do not validate and sanitize user-supplied input properly before passing it to system-level command execution functions. An authenticated adjacent attacker may inject specially crafted input to execute arbitrary operation system commands with elevated privileges.
Successful exploitation may allow execution of arbitrary system commands, potentially leading to full device compromise.
CVSS v4.0 Score: 8.6 / High
CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected Products/Versions and Fixes:
Affected devices include ISP-specific customized variants, e.g. regional or operator-specific versions, deployed and managed by service providers. The table below includes the country-specific generic versions.
|
Product Series |
Model |
CVE-2025-30237 |
CVE-2025-30238 |
CVE-2025-30239 |
CVE-2025-30240 |
CVE-2025-30241 |
Fix version |
|
Mesh: |
HB810(US2) V1.0/1.6/2.0/2.6 |
X |
X |
X |
X |
X |
0.9.0 3.2.2 v6095.0 Build 260717 Rel.67188n |
|
|
HB810(EU1) V2.0 |
X |
X |
X |
X |
X |
0.10.0 3.2.2 v6095.0 Build 260306 Rel.47567n |
|
|
HB710(US2) V1.6/1.0 |
X |
X |
X |
X |
X |
0.3.0 3.0.0 v60be.0 Build 251128 Rel.43956n |
|
|
HB710(EU1) 1.0 |
X |
X |
X |
X |
X |
0.3.0 3.0.0 v60be.0 Build 251128 Rel.43956n |
|
|
HB610(US2) V2.6/2.0 |
X |
X |
X |
X |
X |
0.6.0 3.0.0 v60af.0 Build 251204 Rel.20362n |
|
|
HB610(EU1) |
X |
X |
X |
X |
X |
0.6.0 3.0.0 v60af.0 Build 251204 Rel.20362n |
|
|
HB610(CA) V2.0 |
X |
X |
X |
X |
X |
0.6.0 3.0.0 v60af.0 Build 251216 Rel.46954n |
|
|
HB410( EU1) 1.0 |
X |
X |
X |
X |
X |
0.3.0 3.0.0 v60bf.0 Build 250901 Rel.45574n |
|
|
HB210(US2) 1.0 |
X |
X |
X |
X |
X |
0.2.0 3.0.0 v60f9.0 Build 250826 Rel.47715n |
|
|
HB210(EU1) 1.0 |
X |
X |
X |
X |
X |
0.2.0 3.0.0 v60f9.0 Build 250826 Rel.47715n |
|
|
HB210 Pro(EU1)1.0 |
X |
X |
X |
X |
X |
0.5.0 3.0.0 v60d5.0 Build 250922 Rel.13742n |
|
|
HB210 Pro(US2)1.0/1.6 |
X |
X |
X |
X |
X |
0.8.0 3.0.0 v60d5.0 Build 260318 Rel.78363n |
|
Mesh: |
HX510(US1) V2.0 |
X |
X |
X |
0.14.0 3.0.0 v6065.0 Build 250822 Rel.81150n |
||
|
|
HX510(EU1) V2.0 |
X |
X |
X |
0.14.0 3.0.0 v6065.0 Build 250822 Rel.81150n |
||
|
|
HX510(CA) V1.0/2.0 |
X |
X |
X |
0.14.0 3.0.0 v6065.0 Build 250822 Rel.81150n |
||
|
|
HX510(AU) V1.0/2.0 |
X |
X |
X |
0.14.0 3.0.0 v6065.0 Build 250822 Rel.81150n |
||
|
|
HX510(US2) 2.6 |
X |
X |
X |
0.17.0 3.2.2 v6065.0 Build 260722 Rel.10662n |
||
|
|
HX710(EU1) V1.0 |
X |
X |
X |
0.5.0 3.1.10 v6075.0 Build 260511 Rel.47847n |
||
|
|
HX710 Pro(EU1) V1.0 |
X |
X |
X |
0.4.0 3.1.10 v6082.0 Build 260204 Rel.49460n |
||
|
|
HX220(US1) V1.0/1.0 |
X |
X |
X |
0.21.0 2.0.0 v605f.0 Build 250306 Rel.9224n |
||
|
|
HX220(EU1) V1.0 |
X |
X |
X |
0.21.0 2.0.0 v605f.0 Build 250306 Rel.9224n |
||
|
|
HX220(CA) V1.0 |
X |
X |
X |
0.21.0 2.0.0 v605f.0 Build 250306 Rel.9224n |
||
|
|
HX220(AU) V1.0 |
X |
X |
X |
0.21.0 2.0.0 v605f.0 Build 250306 Rel.9224n |
||
|
|
HX141(EU1) V1.0 |
X |
X |
X |
1.2.0 3.1.0 v609d.0 Build 260128 Rel.29711n |
||
|
Mesh: |
HC220-G5(US1) V1.0/1.6 |
X |
X |
X |
0.18.0 2.0.0 v605e.0 Build 250827 Rel.37904n |
||
|
|
HC220-G5(EU1) V1.20/1.0 |
X |
X |
X |
0.18.0 2.0.0 v605e.0 Build 250827 Rel.37904n |
||
|
|
HC220-G5(BR) V1.30 |
X |
X |
X |
0.17.0 2.0.0 v605e.0 Build 250618 Rel.19329n |
||
|
Router: |
EB210 Pro(EU1) 1.0 |
X |
X |
X |
0.2.0 3.0.0 v60f4.0 Build 250807 Rel.58901n |
||
|
|
EB210 Pro(US1) 1.0 |
X |
X |
X |
0.2.0 3.0.0 v60f4.0 Build 250807 Rel.58901n |
||
|
|
EB810v(EU1) V1.0 |
X |
X |
X |
X |
0.6.0 3.0.0 v608b.0 Build 250613 Rel.10497n |
|
|
Router: |
EC220-G5(BR) V3.0 |
X |
1.14.1 Build 250715 Rel.72650n(4252) |
||||
|
|
EC220-G5(EU1) V3.0 |
X |
1.15.1 Build 260205 Rel.38208n(4555) |
||||
|
|
EC220-G5(US1) V3.0 |
X |
1.14.1 Build 250715 Rel.72650n(4252) |
||||
|
|
EC225-G5(BR) V1.0 |
X |
1.14.1 Build 250717 Rel.34953n(4252) |
||||
|
|
EC225-G5(EU1) V1.0 |
X |
1.14.1 Build 250711 Rel.35878n(4555) |
||||
|
|
EC225-G5(US1) V1.0 |
X |
1.1.14.1 Build 250711 Rel.35607n(5553) |
||||
|
Router: |
EX141(BR) V1.0/1.9 |
X |
X |
X |
1.8.0 3.1.0 v608a.0 Build 250425 Rel.40905n |
||
|
|
EX141(EU1) V1.0 |
X |
X |
X |
1.7.0 3.1.0 v608a.0 Build 250418 Rel.8257n |
||
|
|
EX141(US1) V1.0 |
X |
X |
X |
1.7.0 3.1.0 v608a.0 Build 250418 Rel.8257n |
||
|
|
EX220(BR) V1.0/1.20/1.28/1.29/1.8 |
X |
X |
X |
X |
X |
0.20.0 2.0.0 v605f.0 Build 250305 Rel.14728n |
|
|
EX220(BR) V2.0 |
X |
X |
X |
X |
X |
0.19.0 2.0.0 v609b.0 Build 250814 Rel.49732n |
|
|
EX220(EU1) V1.0/1.20 |
X |
X |
X |
X |
X |
0.20.0 2.0.0 v605f.0 Build 250305 Rel.14728n |
|
|
EX220(RU) V1.0 |
X |
X |
X |
X |
X |
0.20.0 2.0.0 v605f.0 Build 250305 Rel.14728n |
|
|
EX220(US1) V1.0 |
X |
X |
X |
X |
X |
0.20.0 2.0.0 v605f.0 Build 250305 Rel.14728n |
|
|
EX222(EU1) V1.0 |
X |
X |
X |
X |
X |
0.20.0 2.0.0 v605f.0 Build 250305 Rel.14728n |
|
|
EX222(KR) V1.0 |
X |
X |
X |
X |
X |
0.20.0 2.0.0 v609b.0 Build 260427 Rel.16915 |
|
|
EX222(US1) V1.0 |
X |
X |
X |
X |
X |
0.20.0 2.0.0 v605f.0 Build 250305 Rel.14728n |
|
|
EX511(BR) V2.0/2.8/2.9 |
X |
X |
X |
0.9.0 3.0.0 v607e.0 Build 260520 Rel.33425n |
||
|
|
EX511(EU1) V2.0 |
X |
X |
X |
0.9.0 3.0.0 v607e.0 Build 260520 Rel.33425n |
||
|
|
EX511(US1) V2.0 |
X |
X |
X |
0.8.0 3.0.0 v607e.0 Build 260424 Rel.27419n |
||
|
|
EX520(US1) V1.0 |
X |
X |
X |
0.7.0 3.0.0 v60b4.0 Build 251229 Rel.84306n |
||
|
|
EX520v(EU1)1.0 |
X |
X |
X |
X |
X |
0.1.0 3.0.0 v60ee.0 Build 250310 Rel.55637n |
|
|
EX521(US1) V1.0 |
X |
X |
X |
0.3.0 3.0.0 v60e3.0 Build 250925 Rel.66797n |
||
|
|
EX820v(EU1) V1.0 |
X |
X |
X |
X |
x |
0.4.0 3.1.9 v6087.0 Build 250928 Rel.59674n |
|
|
EX920(US2) V1.6/V1.0 |
X |
X |
X |
X |
X |
0.8.0 3.2.2 v6080.0 Build 260309 Rel.54790n |
|
PON: |
XC220-G3v(EU1) V2.30 |
X |
X |
X |
X |
1.16.0 0.8.0 v6062.0 Build 250817 Rel.23310n |
|
|
|
XC220-G3v(US1) V2.30 |
X |
X |
X |
X |
1.16.0 0.8.0 v6062.0 Build 250817 Rel.23310n |
|
|
PON: |
XX530v(BR)v1.0 |
X |
X |
X |
X |
0.6.0 3.0.0 v6096.0 Build 250416 Rel.26048n |
|
|
|
XX530v(BR)v2.0 |
X |
X |
X |
X |
X |
0.4.0 3.1.10 v60dc.0 Build 250520 Rel.69748n |
|
|
XX530v(US1) |
X |
X |
X |
X |
0.6.0 3.0.0 v6096.0 Build 250416 Rel.26048n |
|
|
|
XX530v(EU1) |
X |
X |
X |
X |
X |
0.3.0 3.1.10 v6107.0 Build 250425 Rel.71973n |
|
|
XX230v(BR) V1.0 |
X |
X |
X |
X |
0.16.0 3.0.0 v6066.0 Build 250423 Rel.43799n |
|
|
xDSL Modem: |
VX800v(DE) V1.0 |
X |
X |
X |
X |
X |
800.0.16 |
|
|
VX1800v(EU1) V1.0 |
X |
X |
X |
X |
0.14.0 2.0.0 v6092.0 Build 250417 Rel.24761n |
|
|
|
VX420-G2h(AU) V3.0 |
X |
X |
X |
X |
X |
0.2.0 2.0.0 v60df.0 Build 250427 Rel.38233n |
Notes:
- Firmware is distributed via ISP-managed update mechanisms.
- Detailed SKU-level applicability varies per ISP deployment and is not publicly enumerated.
- An “X” indicates that the model includes variants affected by the corresponding vulnerabilities. Applicability is based on generic model analysis as ISP-specific variants may differ.
Recommendations:
For affected devices running ISP-managed firmware, remediation efforts will be coordinated through the respective Internet Service Providers (ISPs).
Updated firmware may be delivered automatically or made available through supported device update mechanisms, such as the device management interface or associated management applications, depending on the ISP deployment method.
End-users should check their device management interface or associated management application to determine whether a firmware update is available. If no update is available, or if they require additional information regarding update availability, they should contact their ISP for assistance.
Firmware images for affected ISP-specific variants may not be publicly available for direct download.
Disclaimer:
This advisory is provided for informational purposes only and is subject to change without notice. The information is provided “as is” without warranties of any kind. TP-Link recommends that customers promptly apply available firmware updates or implement documented workarounds as provided in this advisory. Devices/systems that are not updated or mitigated as described may remain vulnerable, and TP-Link disclaims any responsibility or liability for any damages or losses arising from a failure to implement such updates.
Looking for More
Is this faq useful?
Your feedback helps improve this site.
TP-Link Community
Still need help? Search for answers, ask questions, and get help from TP-Link experts and other users around the world.