Telecommunications giant TP-Link has identified critical security flaws in 65 router models supplied by internet providers, but due to manufacturer restrictions, customers cannot apply the necessary patches themselves, raising concerns over widespread vulnerability and dependence on service providers for updates.
TP-Link has identified five security flaws across 65 router models supplied by internet providers, but the company says customers cannot apply the fix themselves. In practice, that means the patch must be pushed through the operator that manages the device, leaving many users dependent on their service provider’s update schedule rather than their own action.
The most serious issue, tracked as CVE-2025-30237, affects the web administration interface and can let an attacker reach privileged settings without valid login credentials. The National Vulnerability Database describes it as an authentication bypass in TP-Link Aginet devices, with a high-severity score of 8.7. Security databases including SentinelOne and CVEFeed say the flaw can allow unauthenticated control of the device’s management functions.
TP-Link says the affected firmware has been corrected in version 800.0.16 for at least one example model, the VX800v(DE), but that file is not made available for direct download in operator-managed devices. According to the company’s security notice, remediation has to be coordinated with the relevant internet provider, and the exact impact depends on how each operator has customised its version of the router software. That makes it harder for customers to know whether their own device is affected or when a fix will arrive.
For users, the practical advice is to check the model label on the router and compare it with TP-Link’s affected series, which include prefixes such as HB, HX, HC, EB, EC, EX, XC, XX and VX. The company also recommends checking the firmware version in the device’s system information page. Until an update arrives, security experts advise disabling remote administration and using a guest Wi-Fi network to keep visitors separate from the main home network. The disclosure comes amid broader scrutiny of TP-Link: CISA continues to list other TP-Link flaws in its catalogue of known exploited vulnerabilities, while US authorities have recently taken a harder line on the brand’s hardware and firmware practices.
Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.





