In affected TP-Link Aginet devices, insufficient authorization validation allows authenticated low-privileged users to execute higher-privileged operations.
An attacker may perform administrative actions such as creating privileged accounts or modifying critical configuration settings.