CVE-2025-30241

Severity CVSS v4.0:
HIGH
Type:
CWE-78 OS Command Injections
Publication date:
10/08/2026
Last modified:
10/08/2026

Description

Certain web<br /> interface components in affected TP-Link Aginet devices do not validate and sanitize user-supplied input properly before<br /> passing it to system-level command execution functions.  An authenticated adjacent attacker may inject<br /> specially crafted input to execute arbitrary operation system commands with<br /> elevated privileges.<br /> <br /> <br /> <br /> <br /> <br /> <br /> <br /> <br /> <br /> Successful<br /> exploitation may allow execution of arbitrary system commands, potentially<br /> leading to full device compromise.

References to Advisories, Solutions, and Tools