What is CVE-2025-30237?
CVE-2025-30237 is an authentication bypass vulnerability in the web management interface of TP-Link Aginet devices. Due to inconsistently enforced authentication checks on certain endpoints, an attacker can send specially crafted requests to invoke privileged functionality without valid credentials. Affected users should immediately apply the firmware update released by the vendor.
Azərbaycanca: CVE-2025-30237 TP-Link Aginet cihazlarının veb idarəetmə interfeysində autentifikasiya bypass zəifliyidir. Müəyyən endpoint-lərdə autentifikasiya yoxlanışının düzgün aparılmaması səbəbindən təcavüzkar xüsusi hazırlanmış sorğularla etibarlı giriş məlumatı olmadan imtiyazlı əməliyyatlar icra edə bilər. Təsirlənən cihaz sahibləri istehsalçının buraxdığı proqram təminatı yeniləməsini dərhal tətbiq etməlidir.
Related CVEs
link basis: same weakness class CWE-287
FAQ2
Which devices are affected by CVE-2025-30237?
The vulnerability affects the web management interface of TP-Link Aginet devices.
What should I do to protect against CVE-2025-30237?
Affected users should immediately apply the firmware update released by the vendor.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.