TP-LINK disclosed five vulnerabilities affecting ISP-managed networking devices, including routers and mesh systems. The major issues include authentication bypass and command injection, with CVSS scores reaching up to 8.7. None of these vulnerabilities have been confirmed to be exploited yet. Users are advised to apply the latest security updates provided through their ISPs. The vulnerabilities range in severity, with four categorized as high and one medium.
Specific CVEs include authentication bypass (CVE-2025-30237), privilege escalation (CVE-2025-30238), command injection (CVE-2025-30241), sensitive data exposure (CVE-2025-30239), and arbitrary file read (CVE-2025-30240). It's crucial for users to ensure their devices are updated to mitigate risks.