Symbolic Link Vulnerability in TP-Link Aginet Devices
CVE-2025-30240
5.1MEDIUM
Key Information:
- Vendor
Tp-link Systems Inc.
- Vendor
- CVE Published:
- 10 August 2026
What is CVE-2025-30240?
The TP-Link Aginet devices contain a vulnerability related to improper validation of symbolic links on external USB storage devices. An attacker can exploit this weakness by creating a crafted symbolic link on supported storage media. This could lead to unauthorized read access to sensitive files within the device filesystem, potentially exposing critical data and compromising the security of the device.
Affected Version(s)
EB810v(EU1) V1.0 0 < 0.6.0 3.0.0 v608b.0 Build 250613 Rel.10497n
EX220(BR) V1.0/1.20/1.28/1.29/1.8 0 < 0.20.0 2.0.0 v605f.0 Build 250305 Rel.14728n
EX220(BR) V2.0 0 < 0.19.0 2.0.0 v609b.0 Build 250814 Rel.49732n
References
CVSS V4
Score:
5.1
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Physical
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Gerhard Hechenberger, Stefan Schweighofer, Constantin Schieber-Knoebl from the SEC Consult Vulnerability Lab
