Description
The affected TP-Link Aginet devices do not properly validate symbolic links created on external USB storage
devices. By placing a crafted symbolic link on supported storage media, an
attacker may cause the system to resolve the link.









Successful
exploitation may allow unauthorized read access to sensitive files within the
device filesystem.
Published: 2026-08-10
Score: 5.1 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

TP‑Link AGI.NET devices fail to validate symbolic links stored on removable USB media. By placing a crafted symlink on such media, an attacker can influence the device to resolve the link, allowing unauthorized read access to sensitive files residing in the device filesystem. This flaw results in an information disclosure vulnerability with a CVE‑ID–specific CVSS score of 5.1, indicating moderate severity.

Affected Systems

The affected range includes TP‑Link AGI.NET products such as the EB810v, EX220, EX222, EX520v, EX820v, EX920, HB210, HB410, HB610, HB710, HB810, VX1800v, VX420‑G2h, VX800v, XC220‑G3v, and XX530v running firmware versions from 1.0 through 3.0, across numerous regional variants. All listed models support USB storage and the HTTPS access path that processes symlinks.

Risk and Exploitability

The CVSS score of 5.1 reflects a medium risk level, and the EPSS metric is not available, so the likelihood of widespread exploitation is unclear. The vulnerability does not appear in the CISA KEV catalog. Exploitation requires physical or insider access to attach a USB device containing a malicious symbolic link. Attackers could then read arbitrary files on the router, potentially exposing device configuration or credential data. Because the flaw is tied to USB attachment, typical remote attackers would need local presence or to trick a user into providing the USB drive.

Generated by OpenCVE AI on August 10, 2026 at 23:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the device firmware to the latest version released by TP‑Link that addresses the symlink handling flaw, following instructions available in TP‑Link’s support FAQ (link provided in references).
  • If a firmware update has not yet been distributed, disable the device’s external USB storage capability to eliminate the vectors that rely on removable media.
  • Enable logging for USB mount operations and monitor for abnormal symbolic link creation or file access within the device’s HTTPS service directories.

Generated by OpenCVE AI on August 10, 2026 at 23:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 10 Aug 2026 22:45:00 +0000

Type Values Removed Values Added
Description The affected TP-Link Aginet devices do not properly validate symbolic links created on external USB storage devices. By placing a crafted symbolic link on supported storage media, an attacker may cause the system to resolve the link. Successful exploitation may allow unauthorized read access to sensitive files within the device filesystem.
Title Arbitrary File Read via Improper Symlink Handling in USB HTTPS Access Path in multiple TP-Link Aginet Devices
Weaknesses CWE-59
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: TPLink

Published:

Updated: 2026-08-10T22:25:41.776Z

Reserved: 2025-03-19T11:09:33.245Z

Link: CVE-2025-30240

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-10T23:30:07Z

Weaknesses
  • CWE-59

    Improper Link Resolution Before File Access ('Link Following')