CVE-2025-30237General

LOWCVSS 8.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The affected TP-Link Aginet devices contain a flaw in the web management interface where authentication checks are not consistently enforced on certain endpoints. An attacker can send specially crafted requests to bypass authentication and directly invoke privileged functionality without valid credentials. This issue arises from improper enforcement of access control mechanisms on sensitive operations. Successful exploitation may allow an unauthenticated attacker to execute privileged operations and gain full control of the device.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • General: 1 classified signal
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-08-12); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-08-12: 1Mentions · 2026-08-14: 1Technical Details · 2026-08-14: 108-1208-14
Signal classification2 categories
General
150.0%
Disclosure
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-08-121
General1
2026-08-141
Disclosure1
Full discourse2 posts
  • Total Cyber-Sec@totalcybersec
    Disclosure

    1/6 🔓 CVE-2025-30237 (CVSS 8.7) permite evadir la autenticación en la interfaz web sin credenciales válidas. En un entorno vulnerable, un atacante podría acceder a funciones protegidas y avanzar hacia un compromiso mayor del dispositivo.

    Post summary

    The message announces CVE-2025-30237, citing a CVSS score of 8.7 and describing an authentication bypass that could lead to further device compromise.

    1000048
    15.8K followersView on X
  • SecureShield@SecureShield_
    General

    一次情報(NVD): https://nvd.nist.gov/vuln/detail/CVE-2025-30237 参照元(ベンダー等): https://www.tp-link.com/us/support/faq/5239/

    Post summary

    The post merely references a CVE via two links, offering no additional context, PoC, exploit, or remediation details.

    0000056
    25 followersView on X

Explore more