Executive brief
TP-Link Aginet networking devices used to manage home and small business networks contain a vulnerability in their web-based management console that allows an authenticated attacker to inject malicious commands. An attacker who has valid login credentials could potentially execute arbitrary system commands with elevated privileges, compromising the entire device and any networks it manages.
Technical details
CVE-2025-30241 is an OS command injection vulnerability in web interface components of TP-Link Aginet devices. The vulnerable code fails to properly validate and sanitize user-supplied input before passing it to system-level command execution functions. An authenticated adjacent attacker can craft specially malicious input to inject arbitrary operating system commands that execute with elevated privileges. Successful exploitation allows full device compromise and potential lateral movement into managed networks. Patches are available for affected HB and HX series devices; users should update to the fixed firmware versions listed in the security advisory.
Affected products
- TP-Link Aginet HB810 V1.0, V1.6, V2.0, V2.6 (HB810(US2)); V2.0 (HB810(EU1))
- TP-Link Aginet HB710 V1.0, V1.6 (HB710(US2)); 1.0 (HB710(EU1))
- TP-Link Aginet HB610 V2.0, V2.6 (HB610(US2)); HB610(EU1); V2.0 (HB610(CA))
- TP-Link Aginet HB410 1.0 (HB410(EU1))
- TP-Link Aginet HB210 1.0 (HB210(US2)); 1.0 (HB210(EU1)); 1.0 (HB210 Pro(EU1)); 1.0, 1.6 (HB210 Pro(US2))
- TP-Link Aginet HX510 V2.0 (HX510(US1)); V2.0 (HX510(EU1)); V1.0, V2.0 (HX510(CA)); V1.0, V2.0 (HX510(AU)); 2.6 (HX510(US2))
- TP-Link Aginet HX710 V1.0 (HX710(EU1)); V1.0 (HX710 Pro(EU1))
- TP-Link Aginet HX220 V1.0 (HX220(US1)); V1.0 (HX220(EU1)); V1.0 (HX220(CA)); V1.0 (HX220(AU))
Timeline
- 2026-08-10: disclosed: Security advisory published by TP-Link