Vulnerability
Published 2026-10-08
Verified 2026-10-08

SEC Consult publishes details of five TP-Link ISP router and mesh flaws (CVE-2025-30237 to 30241) across 65 models, including Australian HX510(AU) and HX220(AU) units, as Florida, Iowa, Montana and Nebraska sue TP-Link over security marketing and China ties

SEC Consult published technical details on 8 October 2026 of five vulnerabilities it reported to TP-Link from December 2024 in ISP-supplied (Aginet) mesh systems, routers, fibre (PON) devices and DSL modems. TP-Link says 65 models are affected, including ISP-customised variants; the list includes Australian models HX510(AU) and HX220(AU). CVE-2025-30237 is an authentication bypass in the web server that lets an unauthenticated attacker with access to the web interface create a super-administrator and enable SSH; CVE-2025-30238 lets a low-privileged user act as an administrator; CVE-2025-30241 is authenticated command injection as root; CVE-2025-30239 is hardcoded, model-wide keys protecting configuration files and backups, so extracted keys reveal user, Wi-Fi and sometimes ISP remote-management credentials; CVE-2025-30240 needs physical USB access to read the whole file system. SEC Consult says an attacker on the same network could fully take over a device. TP-Link disclosed the flaws in August 2026; its fixes, including custom ISP firmware, rolled out into 2026 and are distributed by ISPs. Separately, the attorneys general of Florida, Iowa, Montana and Nebraska filed near-identical consumer protection lawsuits against TP-Link Systems on 6 October, after Texas in February, alleging its HomeShield marketing overstated protection, citing past use of TP-Link routers in Volt Typhoon and Flax Typhoon activity, unsupported models without updates, and undisclosed ties to China; they cite these five CVEs. TP-Link's response is not in the reporting. No exploitation of the five flaws is reported. Primary: SEC Consult; wire: SecurityWeek.

Product
TP-Link ISP-managed devices: HB/HX/HC mesh, EB/EC/EX routers, XC/XX PON, VX xDSL series (incl. ISP-custom variants)
Versions
65 models per TP-Link, including HX510(AU) V1.0/2.0 and HX220(AU) V1.0; see TP-Link FAQ 5239 for per-model fixed firmware
CVSS
Not stated in SEC Consult or SecurityWeek reporting; SEC Consult rates impact critical
Exploited in Australia?
unknown
Patch to
Install the fixed firmware listed in TP-Link FAQ 5239. Updates come through your ISP: check the device's admin page or app, and ask your ISP if none is offered. Keep the web interface off untrusted networks.

Primary: SEC Consult Vulnerability Lab — Multiple critical vulnerabilities in multiple TP-Link device series (8 Oct 2026) · Vendor: TP-Link — security advisory and fixed firmware list for affected devices · CVE: CVE-2025-30237, CVE-2025-30238, CVE-2025-30241, CVE-2025-30239, CVE-2025-30240 · SecurityWeek — TP-Link faces state lawsuits and new scrutiny over ISP router flaws (8 Oct 2026)

vulnerabilities australia network