A TP-Link router vulnerability advisory covers 65 of the company’s ISP-managed Aginet models, listing five separate flaws. Four are rated High, up to CVSS 8.7, and the worst lets an attacker bypass authentication on the device’s web server. TP-Link says only internet providers can distribute the fixes.
Which Devices the TP-Link Router Vulnerability List Covers
Only ISP-supplied hardware is affected. The advisory covers the Aginet line, which TP-Link builds for broadband providers to install and manage, rather than the Archer and Deco boxes sold in shops.
TP-Link’s advisory lists 65 model and hardware-revision rows across four product families. The quickest way to tell whether yours is one of them is the letter prefix printed on the label underneath the unit.
| Family | Model prefixes |
|---|---|
| Mesh systems | HB, HX, HC |
| Routers | EB, EC, EX |
| Fibre (PON) devices | XC, XX |
| DSL modems | VX |
Not every listed model carries all five flaws. TP-Link marks them per model and hardware revision, and The Hacker News counts 27 rows flagged for all five. TP-Link adds that “detailed SKU-level applicability varies per ISP deployment and is not publicly enumerated,” which means a provider in one country may ship a variant that behaves differently from the same model elsewhere.
What the Five Flaws Allow
All five sit in the device’s management software rather than its radio or routing. Scores below are TP-Link’s own CVSS version 4.0 ratings.
| CVE | Score | What it allows |
|---|---|---|
| CVE-2025-30237 | 8.7 High | Authentication bypass. Authentication checks are not consistently enforced on some web server endpoints. |
| CVE-2025-30238 | 8.6 High | Privilege escalation. A low-privileged signed-in user can perform administrator actions. |
| CVE-2025-30241 | 8.6 High | Operating system command injection in the web interface, run with elevated privileges. |
| CVE-2025-30239 | 8.5 High | Hardcoded cryptographic keys in the firmware can decrypt stored configuration data, including credentials. |
| CVE-2025-30240 | 5.1 Medium | Arbitrary file read. A crafted symlink on USB storage exposes files on the device. |
The practical worry is the combination. A hardcoded key that decrypts a saved configuration file exposes the Wi-Fi password and, on provider hardware, the credentials the ISP uses for remote management.
As of 10 October 2026 there is no public report of any of these five flaws being exploited. SEC Consult, the Austrian consultancy that found them, published its technical write-up on 8 October but deliberately withheld proof-of-concept exploit code because many devices are still unpatched.
Why Your Provider Controls the Fix
This is the part that separates the story from an ordinary router patch. You cannot fix an affected Aginet device yourself, because TP-Link does not hand you the firmware.
The company’s advisory states plainly that “firmware is distributed via ISP-managed update mechanisms” and that remediation “will be coordinated through the respective Internet Service Providers.” It adds that updates “may be delivered automatically or made available through supported device update mechanisms,” and that firmware images for ISP-specific variants “may not be publicly available for direct download.”
So the patch exists, and whether it reaches your living room depends on a company that did not write it. TP-Link first disclosed the flaws on 10 August 2026 and last updated the advisory on 9 October 2026. The gap between those dates is two months in which an ISP may or may not have pushed anything.
How to Check Your Router This Week
- Read the label on the underside of the unit and note the model and hardware revision, for example HX220 v1.0. The advisory is organised by revision, not model alone.
- Check the prefix against the table above. If the model starts with Archer, Deco or anything else, this advisory does not apply to it.
- Sign in to the device’s management page or your provider’s companion app and look for a firmware update. If you are unsure how to reach the admin page, our guide to setting up a TP-Link router and the 192.168.0.1 router login walkthrough cover the usual addresses and default credentials.
- If no update is offered, contact your internet provider and quote the CVE numbers. TP-Link’s own instruction is that users “should contact their ISP for assistance.”
- Do not try to flash firmware from a public download page onto an ISP-managed unit. TP-Link says the ISP variants are not published, so anything you find will be for a different build.
- Check whether the management interface is reachable from the internet and switch off remote administration if you do not need it. TP-Link says exploitation generally requires network access to that interface, so removing the exposure removes most of the risk while you wait.
The Lawsuits Are About Different Routers
A second TP-Link story broke in the same week, and the two are easy to confuse. They involve different devices.
Florida, Iowa, Montana and Nebraska each sued TP-Link Systems on 6 October 2026 in their own state courts, bringing the total to five states after Texas filed in February. Florida’s complaint, filed in Polk County under the state’s Deceptive and Unfair Trade Practices Act, names the TL-WR940N, Archer C7 versions 2 and 3, and Archer AX21 versions 1 and 1.20. Those are retail models, and the complaints say the Archer AX21 versions reached end of life in May 2024. Florida seeks an injunction, surrender of profits and penalties of $10,000 for each wilful violation.
So the lawsuits concern discontinued consumer routers people bought themselves, while the five CVEs concern current provider hardware people were given. Owning an Archer AX21 does not put you in the advisory, and owning an HX mesh unit does not put you in the lawsuits.
The states also allege that TP-Link overstated its security, citing marketing for its HomeShield service, and concealed its dependence on Chinese operations. Steve Kovsky, TP-Link’s corporate affairs officer, told The Hacker News that “the coordinated lawsuits are built on false premises,” that the company is “an independent, U.S. company that is not owned or controlled by any foreign government,” and that “we do not, and will not, share customer network data with foreign governments or unauthorized third parties.”
Where the Vendor and the Researchers Disagree
TP-Link and SEC Consult describe the headline flaw differently, and the difference matters to how worried an owner should be.
SEC Consult’s account, as reported by SecurityWeek, is that CVE-2025-30237 lets an attacker who can reach the web interface create a super-administrator account and switch on SSH without any credentials at all. TP-Link’s advisory is narrower: it says exploitation generally requires network access “and, in some cases, valid user credentials to the device management interface.”
Neither party has published the test conditions that would settle which description applies to which model. Until one does, the safe reading is the researchers’ version for any unit whose admin page is reachable from outside the home network.
One claim in the complaints also rests on thinner ground than the filings suggest. The states tie TP-Link routers to the Volt Typhoon and Flax Typhoon intrusion campaigns, but The Hacker News reports that the citation traces to 2025 congressional testimony from former National Security Agency cybersecurity director Rob Joyce, who said TP-Link routers “were among the various brands” exploited and whose written testimony names no source. TP-Link says the campaigns showed “no discernible preference for using TP-Link routers as a vector.”
Frequently Asked Questions
Does This TP-Link Router Vulnerability Affect My Archer Router?
No. The five flaws, CVE-2025-30237 to CVE-2025-30241, affect only ISP-managed Aginet devices whose model names start with HB, HX, HC, EB, EC, EX, XC, XX or VX. Archer and Deco models sold at retail are not in TP-Link’s advisory.
How Do I Update an ISP-Supplied TP-Link Router?
Check the device management page or your provider’s app for an available update first. TP-Link says firmware for ISP variants is distributed by the provider and may not be downloadable publicly, so if nothing is offered you need to ask your ISP.
Have These TP-Link Flaws Been Exploited?
No public exploitation has been reported as of 10 October 2026. SEC Consult published technical details on 8 October but held back proof-of-concept exploit code because many devices remain unpatched.
Which States Have Sued TP-Link?
Florida, Iowa, Montana and Nebraska filed on 6 October 2026, joining Texas, which filed in February. The suits concern retail Archer models and marketing claims, not the Aginet flaws, and TP-Link denies the allegations.
Should I Replace My TP-Link Router?
TP-Link’s advisory asks customers to apply available firmware updates rather than replace hardware. If your unit is an end-of-life retail model that no longer receives updates, such as the Archer AX21 versions named in Florida’s complaint, it will not be patched again.




