Impact
TP‑Link AGI.NET devices fail to validate symbolic links stored on removable USB media. By placing a crafted symlink on such media, an attacker can influence the device to resolve the link, allowing unauthorized read access to sensitive files residing in the device filesystem. This flaw results in an information disclosure vulnerability with a CVE‑ID–specific CVSS score of 5.1, indicating moderate severity.
Affected Systems
The affected range includes TP‑Link AGI.NET products such as the EB810v, EX220, EX222, EX520v, EX820v, EX920, HB210, HB410, HB610, HB710, HB810, VX1800v, VX420‑G2h, VX800v, XC220‑G3v, and XX530v running firmware versions from 1.0 through 3.0, across numerous regional variants. All listed models support USB storage and the HTTPS access path that processes symlinks.
Risk and Exploitability
The CVSS score of 5.1 reflects a medium risk level, and the EPSS metric is not available, so the likelihood of widespread exploitation is unclear. The vulnerability does not appear in the CISA KEV catalog. Exploitation requires physical or insider access to attach a USB device containing a malicious symbolic link. Attackers could then read arbitrary files on the router, potentially exposing device configuration or credential data. Because the flaw is tied to USB attachment, typical remote attackers would need local presence or to trick a user into providing the USB drive.
OpenCVE Enrichment