TP-Link has announced several high-severity vulnerabilities impacting its Aginet networking products used by ISPs, such as mesh systems, routers, PON devices, and xDSL modems. These vulnerabilities pose significant security risks, including authentication bypass, privilege escalation, and unauthorized data access.
Key Vulnerability Details
The vulnerabilities, identified as CVE-2025-30237 through CVE-2025-30241, were highlighted in a security advisory updated on August 10, 2026. Internet service providers typically manage these affected products, which means firmware updates may vary depending on the provider and region.
Among the most critical is CVE-2025-30237, an authentication bypass vulnerability in the web management interface with a CVSS v4 score of 8.7. This flaw enables attackers on adjacent networks to access privileged functions without valid credentials, potentially allowing full device control.
Additional High-Severity Flaws
CVE-2025-30238, with a CVSS score of 8.6, involves improper authorization in user-management functions. This issue allows users with limited privileges to perform administrative actions, such as creating privileged accounts or altering device settings, thereby expanding their control.
Another significant flaw, CVE-2025-30239, involves hardcoded cryptographic keys in firmware, rated with a CVSS score of 8.5. Attackers could recover these keys to decrypt sensitive data, exposing credentials and ISP settings.
Other Notable Vulnerabilities and Mitigation
CVE-2025-30240, a medium-severity vulnerability with a CVSS score of 5.1, involves arbitrary file-read issues due to improper handling of symbolic links on USB storage. This could allow physical access to sensitive files through manipulated links.
The last major vulnerability, CVE-2025-30241, is an OS command injection flaw with a CVSS score of 8.6. It allows authenticated attackers to inject commands into system-level functions, potentially gaining complete control over the device.
TP-Link recommends that firmware updates for ISP-managed devices be coordinated through service providers. Users should regularly check for updates via the router administration interface or provider’s app. Additionally, restricting management interface exposure, using strong admin credentials, and disabling unnecessary remote features can help mitigate risks.
