{"id":"CVE-2025-30241","aliases":[],"url":"https://o3.security/vulnerability/CVE-2025-30241","summary":"Certain web\ninterface components in affected TP-Link Aginet devices do not validate and sanitize user-supplied input properly before\npassing it to system-level command execution functions. …","details":"Certain web\ninterface components in affected TP-Link Aginet devices do not validate and sanitize user-supplied input properly before\npassing it to system-level command execution functions.  An authenticated adjacent attacker may inject\nspecially crafted input to execute arbitrary operation system commands with\nelevated privileges.\n\n\n\n\n\n\n\n\n\nSuccessful\nexploitation may allow execution of arbitrary system commands, potentially\nleading to full device compromise.","published":"2026-08-10T23:16:50.670","modified":"2026-08-10T23:16:50.670","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://www.tp-link.com/us/support/faq/5239/"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-08-10T23:16:50.670"}}