What is CVE-2025-30241?
Certain web interface components in affected TP-Link Aginet devices fail to properly validate and sanitize user input before passing it to system-level command execution functions. This allows an authenticated adjacent attacker to inject specially crafted input to execute arbitrary operating system commands. The vulnerability is an OS Command Injection flaw, and updating device firmware is recommended.
Azərbaycanca: TP-Link Aginet cihazlarının veb interfeysində istifadəçi daxiletmələrinin düzgün yoxlanılmaması səbəbindən autentifikasiya olunmuş qonşu şəbəkə hücumçusu xüsusi hazırlanmış giriş vasitəsilə sistem səviyyəsində ixtiyari əməliyyat sistemi əmrləri icra edə bilər. Bu boşluq OS Command Injection zəifliyinə səbəb olur. Cihaz proqram təminatını ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-78; shared vendor: TP-Link
FAQ2
What type of attack does CVE-2025-30241 enable?
This vulnerability is an OS Command Injection flaw that allows an authenticated adjacent attacker to execute arbitrary operating system commands through specially crafted input.
How can TP-Link Aginet devices be protected against CVE-2025-30241?
Updating the device firmware to the latest version is recommended to protect against this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.