Vulnerability Description
The affected TP-Link Aginet devices do not properly validate symbolic links created on external USB storage devices. By placing a crafted symbolic link on supported storage media, an attacker may cause the system to resolve the link. Successful exploitation may allow unauthorized read access to sensitive files within the device filesystem.
Related Weaknesses (CWE)
References
FAQ
What is CVE-2025-30240?
CVE-2025-30240 is a documented vulnerability. The affected TP-Link Aginet devices do not properly validate symbolic links created on external USB storage devices. By placing a crafted symbolic link on supported storage media, an attacker may caus...
How severe is CVE-2025-30240?
CVSS scoring is not yet available for CVE-2025-30240. Check NVD for updates.
Is there a patch for CVE-2025-30240?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.