Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2025-30241

Gravedad CVSS v4.0:
ALTA
Tipo:
CWE-78 Neutralización incorrecta de elementos especiales usados en un comando de sistema operativo (Inyección de comando de sistema operativo)
Fecha de publicación:
10/08/2026
Última modificación:
10/08/2026

Descripción

*** Pendiente de traducción *** Certain web<br /> interface components in affected TP-Link Aginet devices do not validate and sanitize user-supplied input properly before<br /> passing it to system-level command execution functions.  An authenticated adjacent attacker may inject<br /> specially crafted input to execute arbitrary operation system commands with<br /> elevated privileges.<br /> <br /> <br /> <br /> <br /> <br /> <br /> <br /> <br /> <br /> Successful<br /> exploitation may allow execution of arbitrary system commands, potentially<br /> leading to full device compromise.

Referencias a soluciones, herramientas e información