CVE-2025-30241 PUBLISHED

OS Command Injection in Web Interface in Multiple TP-Link Aginet Devices

Assigner: TPLink
Reserved: 19.03.2025 Published: 10.08.2026 Updated: 10.08.2026

Certain web interface components in affected TP-Link Aginet devices do not validate and sanitize user-supplied input properly before passing it to system-level command execution functions.  An authenticated adjacent attacker may inject specially crafted input to execute arbitrary operation system commands with elevated privileges.

Successful exploitation may allow execution of arbitrary system commands, potentially leading to full device compromise.

Metrics

CVSS Vector: CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.6

Product Status

Vendor TP-Link Systems Inc.
Product HB810(US2) V1.0/1.6/2.0/2.6
Versions Default: unaffected
  • affected from 0 to 0.9.0 3.2.2 v6095.0 Build 260717 Rel.67188n (excl.)
Vendor TP-Link Systems Inc.
Product HB810(EU1) V2.0
Versions Default: unaffected
  • affected from 0 to 0.10.0 3.2.2 v6095.0 Build 260306 Rel.47567n (excl.)
Vendor TP-Link Systems Inc.
Product HB710(US2) V1.6/1.0
Versions Default: unaffected
  • affected from 0 to 0.3.0 3.0.0 v60be.0 Build 251128 Rel.43956n (excl.)
Vendor TP-Link Systems Inc.
Product HB710(EU1) 1.0
Versions Default: unaffected
  • affected from 0 to 0.3.0 3.0.0 v60be.0 Build 251128 Rel.43956n (excl.)
Vendor TP-Link Systems Inc.
Product HB610(US2) V2.6/2.0
Versions Default: unaffected
  • affected from 0 to 0.6.0 3.0.0 v60af.0 Build 251204 Rel.20362n (excl.)
Vendor TP-Link Systems Inc.
Product HB610(EU1)
Versions Default: unaffected
  • affected from 0 to 0.6.0 3.0.0 v60af.0 Build 251204 Rel.20362n (excl.)
Vendor TP-Link Systems Inc.
Product HB610(CA) V2.0
Versions Default: unaffected
  • affected from 0 to 0.6.0 3.0.0 v60af.0 Build 251216 Rel.46954n (excl.)
Vendor TP-Link Systems Inc.
Product HB410( EU1) 1.0
Versions Default: unaffected
  • affected from 0 to 0.3.0 3.0.0 v60bf.0 Build 250901 Rel.45574n (excl.)
Vendor TP-Link Systems Inc.
Product HB210(US2) 1.0
Versions Default: unaffected
  • affected from 0 to 0.2.0 3.0.0 v60f9.0 Build 250826 Rel.47715n (excl.)
Vendor TP-Link Systems Inc.
Product HB210(EU1) 1.0
Versions Default: unaffected
  • affected from 0 to 0.2.0 3.0.0 v60f9.0 Build 250826 Rel.47715n (excl.)
Vendor TP-Link Systems Inc.
Product HB210 Pro(EU1)1.0
Versions Default: unaffected
  • affected from 0 to 0.5.0 3.0.0 v60d5.0 Build 250922 Rel.13742n (excl.)
Vendor TP-Link Systems Inc.
Product HB210 Pro(US2)1.0/1.6
Versions Default: unaffected
  • affected from 0 to 0.8.0 3.0.0 v60d5.0 Build 260318 Rel.78363n (excl.)
Vendor TP-Link Systems Inc.
Product EB210 Pro(EU1) 1.0
Versions Default: unaffected
  • affected from 0 to 0.2.0 3.0.0 v60f4.0 Build 250807 Rel.58901n (excl.)
Vendor TP-Link Systems Inc.
Product EB210 Pro(US1) 1.0
Versions Default: unaffected
  • affected from 0 to 0.2.0 3.0.0 v60f4.0 Build 250807 Rel.58901n (excl.)
Vendor TP-Link Systems Inc.
Product EB810v(EU1) V1.0
Versions Default: unaffected
  • affected from 0 to 0.6.0 3.0.0 v608b.0 Build 250613 Rel.10497n (excl.)
Vendor TP-Link Systems Inc.
Product EX220(BR) V1.0/1.20/1.28/1.29/1.8
Versions Default: unaffected
  • affected from 0 to 0.20.0 2.0.0 v605f.0 Build 250305 Rel.14728n (excl.)
Vendor TP-Link Systems Inc.
Product EX220(BR) V2.0
Versions Default: unaffected
  • affected from 0 to 0.19.0 2.0.0 v609b.0 Build 250814 Rel.49732n (excl.)
Vendor TP-Link Systems Inc.
Product EX220(EU1) V1.0/1.20
Versions Default: unaffected
  • affected from 0 to 0.20.0 2.0.0 v605f.0 Build 250305 Rel.14728n (excl.)
Vendor TP-Link Systems Inc.
Product EX220(RU) V1.0
Versions Default: unaffected
  • affected from 0 to 0.20.0 2.0.0 v605f.0 Build 250305 Rel.14728n (excl.)
Vendor TP-Link Systems Inc.
Product EX220(US1) V1.0
Versions Default: unaffected
  • affected from 0 to 0.20.0 2.0.0 v605f.0 Build 250305 Rel.14728n (excl.)
Vendor TP-Link Systems Inc.
Product EX222(EU1) V1.0
Versions Default: unaffected
  • affected from 0 to 0.20.0 2.0.0 v605f.0 Build 250305 Rel.14728n (excl.)
Vendor TP-Link Systems Inc.
Product EX222(KR) V1.0
Versions Default: unaffected
  • affected from 0 to 0.20.0 2.0.0 v609b.0 Build 260427 Rel.16915 (excl.)
Vendor TP-Link Systems Inc.
Product EX222(US1) V1.0
Versions Default: unaffected
  • affected from 0 to 0.20.0 2.0.0 v605f.0 Build 250305 Rel.14728n (excl.)
Vendor TP-Link Systems Inc.
Product EX520v(EU1)1.0
Versions Default: unaffected
  • affected from 0 to 0.1.0 3.0.0 v60ee.0 Build 250310 Rel.55637n (excl.)
Vendor TP-Link Systems Inc.
Product EX820v(EU1) V1.0
Versions Default: unaffected
  • affected from 0 to 0.4.0 3.1.9 v6087.0 Build 250928 Rel.59674n (excl.)
Vendor TP-Link Systems Inc.
Product EX920(US2) V1.6/V1.0
Versions Default: unaffected
  • affected from 0 to 0.8.0 3.2.2 v6080.0 Build 260309 Rel.54790n (excl.)
Vendor TP-Link Systems Inc.
Product XX530v(BR)v2.0
Versions Default: unaffected
  • affected from 0 to 0.4.0 3.1.10 v60dc.0 Build 250520 Rel.69748n (excl.)
Vendor TP-Link Systems Inc.
Product XX530v(EU1)
Versions Default: unaffected
  • affected from 0 to 0.3.0 3.1.10 v6107.0 Build 250425 Rel.71973n (excl.)
Vendor TP-Link Systems Inc.
Product XX230v(BR) V1.0
Versions Default: unaffected
  • affected from 0 to 0.16.0 3.0.0 v6066.0 Build 250423 Rel.43799n (excl.)
Vendor TP-Link Systems Inc.
Product VX800v(DE) V1.0
Versions Default: unaffected
  • affected from 0 to 800.0.16 (excl.)
Vendor TP-Link Systems Inc.
Product VX420-G2h(AU) V3.0
Versions Default: unaffected
  • affected from 0 to 0.2.0 2.0.0 v60df.0 Build 250427 Rel.38233n (excl.)

Credits

  • Gerhard Hechenberger, Stefan Schweighofer, Constantin Schieber-Knoebl from the SEC Consult Vulnerability Lab finder

References

Problem Types

  • CWE-78 Improper neutralization of special elements used in an OS command ('OS command injection') CWE

Impacts

  • CAPEC-88: OS Command Injection