CVE-2025-30241
Severity CVSS v4.0:
HIGH
Type:
CWE-78
OS Command Injections
Publication date:
10/08/2026
Last modified:
10/08/2026
Description
Certain web<br />
interface components in affected TP-Link Aginet devices do not validate and sanitize user-supplied input properly before<br />
passing it to system-level command execution functions. An authenticated adjacent attacker may inject<br />
specially crafted input to execute arbitrary operation system commands with<br />
elevated privileges.<br />
<br />
<br />
<br />
<br />
<br />
<br />
<br />
<br />
<br />
Successful<br />
exploitation may allow execution of arbitrary system commands, potentially<br />
leading to full device compromise.
Impact
Base Score 4.0
8.60
Severity 4.0
HIGH



