Impact
The vulnerability stems from the use of hard‑coded cryptographic keys within the firmware of certain TP‑Link Aginet devices. These keys are stored in the device’s persistent memory and are used to encrypt sensitive configuration data. An attacker who gains physical or local access to the device storage can extract the keys, decrypt the confidential data, and obtain credentials and other service‑related information. The weakness is a flaw in cryptographic key management (CWE‑321), allowing a breach of confidentiality but not affecting integrity or availability directly.
Affected Systems
The affected products are TP‑Link Systems Inc. routers and network devices identified by the following models and firmware versions: EB210 Pro (EU1/US1) 1.0, EB810v (EU1) V1.0, EC220‑G5 (BR/EU1/US1) V3.0, EC225‑G5 (BR/EU1/US1) V1.0, EX141 (BR/EU1/US1) V1.0/1.9, EX220 (BR) V1.0/1.20/1.28/1.29/1.8, EX220 (BR) V2.0, EX220 (EU1) V1.0/1.20, EX220 (RU) V1.0, EX220 (US1) V1.0, EX222 (EU1) V1.0, EX222 (KR) V1.0, EX222 (US1) V1.0, EX511 (BR) V2.0/2.8/2.9, EX511 (EU1) V2.0, EX511 (US1) V2.0, EX520 (US1) V1.0, EX520v (EU1)1.0, EX521 (US1) V1.0, EX820v (EU1) V1.0, EX920 (US2) V1.6/V1.0, HB210 Pro (EU1)1.0, HB210 Pro (US2)1.0/1.6, HB210 (EU1)1.0, HB210 (US2)1.0, HB410 (EU1)1.0, HB610 (CA) V2.0, HB610 (EU1), HB610 (US2) V2.6/2.0, HB710 (EU1)1.0, HB710 (US2) V1.6/1.0, HB810 (EU1) V2.0, HB810 (US2) V1.0/1.6/2.0/2.6, HC220‑G5 (BR) V1.30, HC220‑G5 (EU1) V1.20/1.0, HC220‑G5 (US1) V1.0/1.6, HX141 (EU1) V1.0, HX220 (AU/CA/EU1/US1) V1.0, HX510 (AU/CA/EU1/US1/US2) V1.0/2.0 / V2.0 / 2.6, HX710 Pro (EU1) V1.0, HX710 (EU1) V1.0, VX1800v (EU1) V1.0, VX420‑G2h (AU) V3.0, VX800v (DE) V1.0, XC220‑G3v (EU1/US1) V2.30, XX230v (BR) V1.0, XX530v (BR) v1.0/v2.0, XX530v (EU1/US1) with no explicit firmware version listed. The vulnerability covers all firmware versions listed above.
Risk and Exploitability
With a CVSS score of 8.5 the vulnerability is considered high severity. The EPSS score is not available, and the vulnerability is not currently listed in the CISA KEV catalog. The attack requires the attacker to have direct access to the device’s storage, which may be achieved through physical compromise, removable media access, or exploiting local firmware interfaces. Once the keys are recovered, the attacker can decrypt stored configuration data, leading to disclosure of passwords, service addresses, and other sensitive information. Therefore, the risk to confidentiality is significant, particularly for environments where an attacker could obtain local device access.
OpenCVE Enrichment