Description
In affected TP-Link Aginet devices, use of
hardcoded cryptographic keys embedded in the firmware to protect sensitive
configuration data may allow an attacker who has access to device storage to
recover the keys and decrypt stored data.





Successful
exploitation may allow access to decrypted sensitive configuration data,
including credentials and service-related information.
Published: 2026-08-10
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability stems from the use of hard‑coded cryptographic keys within the firmware of certain TP‑Link Aginet devices. These keys are stored in the device’s persistent memory and are used to encrypt sensitive configuration data. An attacker who gains physical or local access to the device storage can extract the keys, decrypt the confidential data, and obtain credentials and other service‑related information. The weakness is a flaw in cryptographic key management (CWE‑321), allowing a breach of confidentiality but not affecting integrity or availability directly.

Affected Systems

The affected products are TP‑Link Systems Inc. routers and network devices identified by the following models and firmware versions: EB210 Pro (EU1/US1) 1.0, EB810v (EU1) V1.0, EC220‑G5 (BR/EU1/US1) V3.0, EC225‑G5 (BR/EU1/US1) V1.0, EX141 (BR/EU1/US1) V1.0/1.9, EX220 (BR) V1.0/1.20/1.28/1.29/1.8, EX220 (BR) V2.0, EX220 (EU1) V1.0/1.20, EX220 (RU) V1.0, EX220 (US1) V1.0, EX222 (EU1) V1.0, EX222 (KR) V1.0, EX222 (US1) V1.0, EX511 (BR) V2.0/2.8/2.9, EX511 (EU1) V2.0, EX511 (US1) V2.0, EX520 (US1) V1.0, EX520v (EU1)1.0, EX521 (US1) V1.0, EX820v (EU1) V1.0, EX920 (US2) V1.6/V1.0, HB210 Pro (EU1)1.0, HB210 Pro (US2)1.0/1.6, HB210 (EU1)1.0, HB210 (US2)1.0, HB410 (EU1)1.0, HB610 (CA) V2.0, HB610 (EU1), HB610 (US2) V2.6/2.0, HB710 (EU1)1.0, HB710 (US2) V1.6/1.0, HB810 (EU1) V2.0, HB810 (US2) V1.0/1.6/2.0/2.6, HC220‑G5 (BR) V1.30, HC220‑G5 (EU1) V1.20/1.0, HC220‑G5 (US1) V1.0/1.6, HX141 (EU1) V1.0, HX220 (AU/CA/EU1/US1) V1.0, HX510 (AU/CA/EU1/US1/US2) V1.0/2.0 / V2.0 / 2.6, HX710 Pro (EU1) V1.0, HX710 (EU1) V1.0, VX1800v (EU1) V1.0, VX420‑G2h (AU) V3.0, VX800v (DE) V1.0, XC220‑G3v (EU1/US1) V2.30, XX230v (BR) V1.0, XX530v (BR) v1.0/v2.0, XX530v (EU1/US1) with no explicit firmware version listed. The vulnerability covers all firmware versions listed above.

Risk and Exploitability

With a CVSS score of 8.5 the vulnerability is considered high severity. The EPSS score is not available, and the vulnerability is not currently listed in the CISA KEV catalog. The attack requires the attacker to have direct access to the device’s storage, which may be achieved through physical compromise, removable media access, or exploiting local firmware interfaces. Once the keys are recovered, the attacker can decrypt stored configuration data, leading to disclosure of passwords, service addresses, and other sensitive information. Therefore, the risk to confidentiality is significant, particularly for environments where an attacker could obtain local device access.

Generated by OpenCVE AI on August 10, 2026 at 23:16 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update all affected TP‑Link devices to the latest firmware revision that removes hard‑coded cryptographic keys, as recommended in the vendor advisory.
  • If a device cannot be updated, isolate the device from uncontrolled networks and restrict physical access to prevent tampering with its storage.
  • After the firmware update, change all administrative credentials and review configuration files to ensure that no residual sensitive data remains stored in plaintext.

Generated by OpenCVE AI on August 10, 2026 at 23:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 11 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Tp-link
Tp-link eb210 Pro(eu1) 1.0
Tp-link eb210 Pro(us1) 1.0
Tp-link eb810v(eu1) V1.0
Tp-link ec220-g5(br) V3.0
Tp-link ec220-g5(eu1) V3.0
Tp-link ec220-g5(us1) V3.0
Tp-link ec225-g5(br) V1.0
Tp-link ec225-g5(eu1) V1.0
Tp-link ec225-g5(us1) V1.0
Tp-link ex141(br) V1.0/1.9
Tp-link ex141(eu1) V1.0
Tp-link ex141(us1) V1.0
Tp-link ex220(br) V1.0/1.20/1.28/1.29/1.8
Tp-link ex220(br) V2.0
Tp-link ex220(eu1) V1.0/1.20
Tp-link ex220(ru) V1.0
Tp-link ex220(us1) V1.0
Tp-link ex222(eu1) V1.0
Tp-link ex222(kr) V1.0
Tp-link ex222(us1) V1.0
Tp-link ex511(br) V2.0/2.8/2.9
Tp-link ex511(eu1) V2.0
Tp-link ex511(us1) V2.0
Tp-link ex520(us1) V1.0
Tp-link ex520v(eu1)1.0
Tp-link ex521(us1) V1.0
Tp-link ex820v(eu1) V1.0
Tp-link ex920(us2) V1.6/v1.0
Tp-link hb210(eu1) 1.0
Tp-link hb210(us2) 1.0
Tp-link hb210 Pro(eu1)1.0
Tp-link hb210 Pro(us2)1.0/1.6
Tp-link hb410( Eu1) 1.0
Tp-link hb610(ca) V2.0
Tp-link hb610(eu1)
Tp-link hb610(us2) V2.6/2.0
Tp-link hb710(eu1) 1.0
Tp-link hb710(us2) V1.6/1.0
Tp-link hb810(eu1) V2.0
Tp-link hb810(us2) V1.0/1.6/2.0/2.6
Tp-link hc220-g5(br) V1.30
Tp-link hc220-g5(eu1) V1.20/1.0
Tp-link hc220-g5(us1) V1.0/1.6
Tp-link hx141(eu1) V1.0
Tp-link hx220(au) V1.0
Tp-link hx220(ca) V1.0
Tp-link hx220(eu1) V1.0
Tp-link hx220(us1) V1.0/1.0
Tp-link hx510(au) V1.0/2.0
Tp-link hx510(ca) V1.0/2.0
Tp-link hx510(eu1) V2.0
Tp-link hx510(us1) V2.0
Tp-link hx510(us2) 2.6
Tp-link hx710(eu1) V1.0
Tp-link hx710 Pro(eu1) V1.0
Tp-link vx1800v(eu1) V1.0
Tp-link vx420-g2h(au) V3.0
Tp-link vx800v(de) V1.0
Tp-link xc220-g3v(eu1) V2.30
Tp-link xc220-g3v(us1) V2.30
Tp-link xx230v(br) V1.0
Tp-link xx530v(br)v1.0
Tp-link xx530v(br)v2.0
Tp-link xx530v(eu1)
Tp-link xx530v(us1)
Vendors & Products Tp-link
Tp-link eb210 Pro(eu1) 1.0
Tp-link eb210 Pro(us1) 1.0
Tp-link eb810v(eu1) V1.0
Tp-link ec220-g5(br) V3.0
Tp-link ec220-g5(eu1) V3.0
Tp-link ec220-g5(us1) V3.0
Tp-link ec225-g5(br) V1.0
Tp-link ec225-g5(eu1) V1.0
Tp-link ec225-g5(us1) V1.0
Tp-link ex141(br) V1.0/1.9
Tp-link ex141(eu1) V1.0
Tp-link ex141(us1) V1.0
Tp-link ex220(br) V1.0/1.20/1.28/1.29/1.8
Tp-link ex220(br) V2.0
Tp-link ex220(eu1) V1.0/1.20
Tp-link ex220(ru) V1.0
Tp-link ex220(us1) V1.0
Tp-link ex222(eu1) V1.0
Tp-link ex222(kr) V1.0
Tp-link ex222(us1) V1.0
Tp-link ex511(br) V2.0/2.8/2.9
Tp-link ex511(eu1) V2.0
Tp-link ex511(us1) V2.0
Tp-link ex520(us1) V1.0
Tp-link ex520v(eu1)1.0
Tp-link ex521(us1) V1.0
Tp-link ex820v(eu1) V1.0
Tp-link ex920(us2) V1.6/v1.0
Tp-link hb210(eu1) 1.0
Tp-link hb210(us2) 1.0
Tp-link hb210 Pro(eu1)1.0
Tp-link hb210 Pro(us2)1.0/1.6
Tp-link hb410( Eu1) 1.0
Tp-link hb610(ca) V2.0
Tp-link hb610(eu1)
Tp-link hb610(us2) V2.6/2.0
Tp-link hb710(eu1) 1.0
Tp-link hb710(us2) V1.6/1.0
Tp-link hb810(eu1) V2.0
Tp-link hb810(us2) V1.0/1.6/2.0/2.6
Tp-link hc220-g5(br) V1.30
Tp-link hc220-g5(eu1) V1.20/1.0
Tp-link hc220-g5(us1) V1.0/1.6
Tp-link hx141(eu1) V1.0
Tp-link hx220(au) V1.0
Tp-link hx220(ca) V1.0
Tp-link hx220(eu1) V1.0
Tp-link hx220(us1) V1.0/1.0
Tp-link hx510(au) V1.0/2.0
Tp-link hx510(ca) V1.0/2.0
Tp-link hx510(eu1) V2.0
Tp-link hx510(us1) V2.0
Tp-link hx510(us2) 2.6
Tp-link hx710(eu1) V1.0
Tp-link hx710 Pro(eu1) V1.0
Tp-link vx1800v(eu1) V1.0
Tp-link vx420-g2h(au) V3.0
Tp-link vx800v(de) V1.0
Tp-link xc220-g3v(eu1) V2.30
Tp-link xc220-g3v(us1) V2.30
Tp-link xx230v(br) V1.0
Tp-link xx530v(br)v1.0
Tp-link xx530v(br)v2.0
Tp-link xx530v(eu1)
Tp-link xx530v(us1)

Tue, 11 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 10 Aug 2026 22:45:00 +0000

Type Values Removed Values Added
Description In affected TP-Link Aginet devices, use of hardcoded cryptographic keys embedded in the firmware to protect sensitive configuration data may allow an attacker who has access to device storage to recover the keys and decrypt stored data. Successful exploitation may allow access to decrypted sensitive configuration data, including credentials and service-related information.
Title Sensitive Data Exposure due to Hardcoded Cryptographic Keys in Multiple TP-Link Aginet Devices
Weaknesses CWE-321
References
Metrics cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Tp-link Eb210 Pro(eu1) 1.0 Eb210 Pro(us1) 1.0 Eb810v(eu1) V1.0 Ec220-g5(br) V3.0 Ec220-g5(eu1) V3.0 Ec220-g5(us1) V3.0 Ec225-g5(br) V1.0 Ec225-g5(eu1) V1.0 Ec225-g5(us1) V1.0 Ex141(br) V1.0/1.9 Ex141(eu1) V1.0 Ex141(us1) V1.0 Ex220(br) V1.0/1.20/1.28/1.29/1.8 Ex220(br) V2.0 Ex220(eu1) V1.0/1.20 Ex220(ru) V1.0 Ex220(us1) V1.0 Ex222(eu1) V1.0 Ex222(kr) V1.0 Ex222(us1) V1.0 Ex511(br) V2.0/2.8/2.9 Ex511(eu1) V2.0 Ex511(us1) V2.0 Ex520(us1) V1.0 Ex520v(eu1)1.0 Ex521(us1) V1.0 Ex820v(eu1) V1.0 Ex920(us2) V1.6/v1.0 Hb210(eu1) 1.0 Hb210(us2) 1.0 Hb210 Pro(eu1)1.0 Hb210 Pro(us2)1.0/1.6 Hb410( Eu1) 1.0 Hb610(ca) V2.0 Hb610(eu1) Hb610(us2) V2.6/2.0 Hb710(eu1) 1.0 Hb710(us2) V1.6/1.0 Hb810(eu1) V2.0 Hb810(us2) V1.0/1.6/2.0/2.6 Hc220-g5(br) V1.30 Hc220-g5(eu1) V1.20/1.0 Hc220-g5(us1) V1.0/1.6 Hx141(eu1) V1.0 Hx220(au) V1.0 Hx220(ca) V1.0 Hx220(eu1) V1.0 Hx220(us1) V1.0/1.0 Hx510(au) V1.0/2.0 Hx510(ca) V1.0/2.0 Hx510(eu1) V2.0 Hx510(us1) V2.0 Hx510(us2) 2.6 Hx710(eu1) V1.0 Hx710 Pro(eu1) V1.0 Vx1800v(eu1) V1.0 Vx420-g2h(au) V3.0 Vx800v(de) V1.0 Xc220-g3v(eu1) V2.30 Xc220-g3v(us1) V2.30 Xx230v(br) V1.0 Xx530v(br)v1.0 Xx530v(br)v2.0 Xx530v(eu1) Xx530v(us1)
cve-icon MITRE

Status: PUBLISHED

Assigner: TPLink

Published:

Updated: 2026-08-11T14:49:10.875Z

Reserved: 2025-03-19T11:09:33.244Z

Link: CVE-2025-30239

cve-icon Vulnrichment

Updated: 2026-08-11T14:49:07.565Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-10T23:16:50.173

Modified: 2026-08-18T15:04:46.610

Link: CVE-2025-30239

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-11T14:21:27Z

Weaknesses
  • CWE-321

    Use of Hard-coded Cryptographic Key