AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2025-30240

MEDIUM · CVSS 5.1 EPSS 0.17% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-10 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

TP-Link Aginet devices are vulnerable due to improper validation of symbolic links on external USB storage, allowing attackers to exploit crafted links. This could lead to unauthorized read access to sensitive files within the device's filesystem. Organizations using these devices should prioritize patching to mitigate potential data exposure risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2025-30240
Severity
MEDIUM
CVSS
5.1
EPSS
0.17%

Original NVD Description

The affected TP-Link Aginet devices do not properly validate symbolic links created on external USB storage devices. By placing a crafted symbolic link on supported storage media, an attacker may cause the system to resolve the link. Successful exploitation may allow unauthorized read access to sensitive files within the device filesystem.