The affected TP-Link Aginet devices do not properly validate symbolic links created on external USB storage
devices. By placing a crafted symbolic link on supported storage media, an
attacker may cause the system to resolve the link.
Successful
exploitation may allow unauthorized read access to sensitive files within the
device filesystem.
CVSS
No CVSS.
References
| Link | Resource |
|---|---|
| https://www.tp-link.com/us/support/faq/5239/ |
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-10 23:16
Updated : 2026-08-18 15:04
NVD link : CVE-2025-30240
Mitre link : CVE-2025-30240
CVE.ORG link : CVE-2025-30240
JSON object : View
Products Affected
No product.
CWE
CWE-59
Improper Link Resolution Before File Access ('Link Following')
