TL;DR
TP-Link disclosed five vulnerabilities across its ISP-managed networking gear. The flaws hit mesh systems, routers, PON devices, and xDSL modems. The worst allow authentication bypass and command injection, with CVSS scores up to 8.7. No exploitation has been confirmed.
- Total: 5 CVEs
- Severity: 4 High · 1 Medium
- Actively exploited: None confirmed
- Highest severity: 8.7 (High · CVSSv4) — CVE-2025-30237
- Action: Apply the latest security updates now
Notable CVEs
| CVE | CVSS (CVSSv4) | Type | Fixed in | Status |
|---|---|---|---|---|
| CVE-2025-30237 | 8.7 | Authentication Bypass via Broken Access Control in Web Server in Multiple TP-Link Aginet Devices | 0.9.0 3.2.2 v6095.0 Build 260717 Rel.67188n, 0.10.0 3.2.2 v6095.0 Build 260306 Rel.47567n, 0.3.0 3.0.0 v60be.0 Build 251128 Rel.43956n (+34) | Not exploited |
| CVE-2025-30238 | 8.6 | Privilege Escalation via Improper Authorization in User Management in multiple TP-Link Aginet Devices | 0.9.0 3.2.2 v6095.0 Build 260717 Rel.67188n, 0.10.0 3.2.2 v6095.0 Build 260306 Rel.47567n, 0.3.0 3.0.0 v60be.0 Build 251128 Rel.43956n (+36) | Not exploited |
| CVE-2025-30241 | 8.6 | OS Command Injection in Web Interface in Multiple TP-Link Aginet Devices | 0.9.0 3.2.2 v6095.0 Build 260717 Rel.67188n, 0.10.0 3.2.2 v6095.0 Build 260306 Rel.47567n, 0.3.0 3.0.0 v60be.0 Build 251128 Rel.43956n (+19) | Not exploited |
| CVE-2025-30239 | 8.5 | Sensitive Data Exposure due to Hardcoded Cryptographic Keys in Multiple TP-Link Aginet Devices | 0.9.0 3.2.2 v6095.0 Build 260717 Rel.67188n, 0.10.0 3.2.2 v6095.0 Build 260306 Rel.47567n, 0.3.0 3.0.0 v60be.0 Build 251128 Rel.43956n (+41) | Not exploited |
| CVE-2025-30240 | 5.1 | Arbitrary File Read via Improper Symlink Handling in USB HTTPS Access Path in multiple TP-Link Aginet Devices | 0.9.0 3.2.2 v6095.0 Build 260717 Rel.67188n, 0.10.0 3.2.2 v6095.0 Build 260306 Rel.47567n, 0.3.0 3.0.0 v60be.0 Build 251128 Rel.43956n (+20) | Not exploited |
Why it matters
Home routers sit at the edge of every network. So a flaw there can expose every device behind it. These TP-Link router vulnerabilities affect ISP-supplied hardware used by many households.
Several flaws score in the high range. As a result, an attacker could seize control of an affected device. That risk grows because users rarely patch their own routers.
How the attacks work
The five bugs span different weaknesses. According to TP-Link, CVE-2025-30237 allows an authentication bypass in the web management interface. It carries a CVSS score of 8.7.
Other issues raise the stakes further. CVE-2025-30238 enables privilege escalation in user management. CVE-2025-30239 exposes hardcoded cryptographic keys. Finally, CVE-2025-30241 permits OS command injection through web interface components.
Exploitation conditions vary
Exploitation needs differ by flaw. Some attacks require adjacent network access or valid credentials. Others trigger through crafted unauthenticated requests, TP-Link says.
So far, no public proof-of-concept or in-the-wild abuse has been confirmed. Still, TP-Link routers draw steady attacker interest. Two other TP-Link flaws already sit on CISA’s exploited-vulnerabilities list.
Affected versions
The affected list is broad. It spans the HB, HX, HC, EB, EC, EX, XC, XX, and VX product families. Exact applicability varies by ISP deployment and region.
Patch and mitigation steps
Fixes ship through each ISP, not directly to users. Therefore, check your device management interface for an available update. TP-Link outlines the full model list and guidance in its official security advisory.
If no update appears, contact your internet provider. Meanwhile, restrict remote management on any exposed router.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.