Symbolic Link Vulnerability in TP-Link Aginet Devices
CVE-2025-30240

5.1MEDIUM

What is CVE-2025-30240?

The TP-Link Aginet devices contain a vulnerability related to improper validation of symbolic links on external USB storage devices. An attacker can exploit this weakness by creating a crafted symbolic link on supported storage media. This could lead to unauthorized read access to sensitive files within the device filesystem, potentially exposing critical data and compromising the security of the device.

Affected Version(s)

EB810v(EU1) V1.0 0 < 0.6.0 3.0.0 v608b.0 Build 250613 Rel.10497n

EX220(BR) V1.0/1.20/1.28/1.29/1.8 0 < 0.20.0 2.0.0 v605f.0 Build 250305 Rel.14728n

EX220(BR) V2.0 0 < 0.19.0 2.0.0 v609b.0 Build 250814 Rel.49732n

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Physical
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Gerhard Hechenberger, Stefan Schweighofer, Constantin Schieber-Knoebl from the SEC Consult Vulnerability Lab
.