Authentication Bypass via Broken Access Control in Web Server in Multiple TP-Link Aginet Devices

Note: This data is for reference and cybersecurity research purposes only.CyStack advises users not to use this information for unlawful purposes.

What is CVE-2025-30237?

CVE-2025-30237 is a vulnerability classified as Missing Authorization, affecting HB810(US2) V1.0/1.6/2.0/2.6 (affected versions: < 0.9.0 3.2.2 v6095.0 Build 260717 Rel.67188n), HB810(EU1) V2.0 (affected versions: < 0.10.0 3.2.2 v6095.0 Build 260306 Rel.47567n), HB710(US2) V1.6/1.0 (affected versions: < 0.3.0 3.0.0 v60be.0 Build 251128 Rel.43956n), and 53 more products. This vulnerability is rated High, with a CVSS score of 8.7. Current sources do not report this vulnerability as exploited.

Analyzing data...

Overview

Original source data

The affected TP-Link Aginet devices contain a flaw in the web management interface where authentication checks are not consistently enforced on certain endpoints. An attacker can send specially crafted requests to bypass authentication and directly invoke privileged functionality without valid credentials. This issue arises from improper enforcement of access control mechanisms on sensitive operations.

Successful exploitation may allow an unauthenticated attacker to execute privileged operations and gain full control of the device.

Affected products and scope

The analysis could not be completed. The original vulnerability data remains available below.

Technical details

The analysis could not be completed. The original vulnerability data remains available below.

Exploitability

The analysis could not be completed. The original vulnerability data remains available below.

Technical impact

The analysis could not be completed. The original vulnerability data remains available below.

Business impact

The analysis could not be completed. The original vulnerability data remains available below.

Remediation

The analysis could not be completed. The original vulnerability data remains available below.

Detection

The analysis could not be completed. The original vulnerability data remains available below.
Sources (6)
Learn more

Run an in-depth assessment with complete web risk management

CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.

Explore CyStack VulnScan