CVE-2025-30240 PUBLISHED

Arbitrary File Read via Improper Symlink Handling in USB HTTPS Access Path in multiple TP-Link Aginet Devices

Assigner: TPLink
Reserved: 19.03.2025 Published: 10.08.2026 Updated: 10.08.2026

The affected TP-Link Aginet devices do not properly validate symbolic links created on external USB storage devices. By placing a crafted symbolic link on supported storage media, an attacker may cause the system to resolve the link.

Successful exploitation may allow unauthorized read access to sensitive files within the device filesystem.

Metrics

CVSS Vector: CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 5.1

Product Status

Vendor TP-Link Systems Inc.
Product HB810(US2) V1.0/1.6/2.0/2.6
Versions Default: unaffected
  • affected from 0 to 0.9.0 3.2.2 v6095.0 Build 260717 Rel.67188n (excl.)
Vendor TP-Link Systems Inc.
Product HB810(EU1) V2.0
Versions Default: unaffected
  • affected from 0 to 0.10.0 3.2.2 v6095.0 Build 260306 Rel.47567n (excl.)
Vendor TP-Link Systems Inc.
Product HB710(US2) V1.6/1.0
Versions Default: unaffected
  • affected from 0 to 0.3.0 3.0.0 v60be.0 Build 251128 Rel.43956n (excl.)
Vendor TP-Link Systems Inc.
Product HB710(EU1) 1.0
Versions Default: unaffected
  • affected from 0 to 0.3.0 3.0.0 v60be.0 Build 251128 Rel.43956n (excl.)
Vendor TP-Link Systems Inc.
Product HB610(US2) V2.6/2.0
Versions Default: unaffected
  • affected from 0 to 0.6.0 3.0.0 v60af.0 Build 251204 Rel.20362n (excl.)
Vendor TP-Link Systems Inc.
Product HB610(EU1)
Versions Default: unaffected
  • affected from 0 to 0.6.0 3.0.0 v60af.0 Build 251204 Rel.20362n (excl.)
Vendor TP-Link Systems Inc.
Product HB610(CA) V2.0
Versions Default: unaffected
  • affected from 0 to 0.6.0 3.0.0 v60af.0 Build 251216 Rel.46954n (excl.)
Vendor TP-Link Systems Inc.
Product HB410( EU1) 1.0
Versions Default: unaffected
  • affected from 0 to 0.3.0 3.0.0 v60bf.0 Build 250901 Rel.45574n (excl.)
Vendor TP-Link Systems Inc.
Product HB210(US2) 1.0
Versions Default: unaffected
  • affected from 0 to 0.2.0 3.0.0 v60f9.0 Build 250826 Rel.47715n (excl.)
Vendor TP-Link Systems Inc.
Product HB210(EU1) 1.0
Versions Default: unaffected
  • affected from 0 to 0.2.0 3.0.0 v60f9.0 Build 250826 Rel.47715n (excl.)
Vendor TP-Link Systems Inc.
Product HB210 Pro(EU1)1.0
Versions Default: unaffected
  • affected from 0 to 0.5.0 3.0.0 v60d5.0 Build 250922 Rel.13742n (excl.)
Vendor TP-Link Systems Inc.
Product HB210 Pro(US2)1.0/1.6
Versions Default: unaffected
  • affected from 0 to 0.8.0 3.0.0 v60d5.0 Build 260318 Rel.78363n (excl.)
Vendor TP-Link Systems Inc.
Product EB810v(EU1) V1.0
Versions Default: unaffected
  • affected from 0 to 0.6.0 3.0.0 v608b.0 Build 250613 Rel.10497n (excl.)
Vendor TP-Link Systems Inc.
Product EX220(BR) V1.0/1.20/1.28/1.29/1.8
Versions Default: unaffected
  • affected from 0 to 0.20.0 2.0.0 v605f.0 Build 250305 Rel.14728n (excl.)
Vendor TP-Link Systems Inc.
Product EX220(BR) V2.0
Versions Default: unaffected
  • affected from 0 to 0.19.0 2.0.0 v609b.0 Build 250814 Rel.49732n (excl.)
Vendor TP-Link Systems Inc.
Product EX220(EU1) V1.0/1.20
Versions Default: unaffected
  • affected from 0 to 0.20.0 2.0.0 v605f.0 Build 250305 Rel.14728n (excl.)
Vendor TP-Link Systems Inc.
Product EX220(RU) V1.0
Versions Default: unaffected
  • affected from 0 to 0.20.0 2.0.0 v605f.0 Build 250305 Rel.14728n (excl.)
Vendor TP-Link Systems Inc.
Product EX220(US1) V1.0
Versions Default: unaffected
  • affected from 0 to 0.20.0 2.0.0 v605f.0 Build 250305 Rel.14728n (excl.)
Vendor TP-Link Systems Inc.
Product EX222(EU1) V1.0
Versions Default: unaffected
  • affected from 0 to 0.20.0 2.0.0 v605f.0 Build 250305 Rel.14728n (excl.)
Vendor TP-Link Systems Inc.
Product EX222(KR) V1.0
Versions Default: unaffected
  • affected from 0 to 0.20.0 2.0.0 v609b.0 Build 260427 Rel.16915 (excl.)
Vendor TP-Link Systems Inc.
Product EX222(US1) V1.0
Versions Default: unaffected
  • affected from 0 to 0.20.0 2.0.0 v605f.0 Build 250305 Rel.14728n (excl.)
Vendor TP-Link Systems Inc.
Product EX520v(EU1)1.0
Versions Default: unaffected
  • affected from 0 to 0.1.0 3.0.0 v60ee.0 Build 250310 Rel.55637n (excl.)
Vendor TP-Link Systems Inc.
Product EX820v(EU1) V1.0
Versions Default: unaffected
  • affected from 0 to 0.4.0 3.1.9 v6087.0 Build 250928 Rel.59674n (excl.)
Vendor TP-Link Systems Inc.
Product EX920(US2) V1.6/V1.0
Versions Default: unaffected
  • affected from 0 to 0.8.0 3.2.2 v6080.0 Build 260309 Rel.54790n (excl.)
Vendor TP-Link Systems Inc.
Product XC220-G3v(EU1) V2.30
Versions Default: unaffected
  • affected from 0 to 1.16.0 0.8.0 v6062.0 Build 250817 Rel.23310n (excl.)
Vendor TP-Link Systems Inc.
Product XC220-G3v(US1) V2.30
Versions Default: unaffected
  • affected from 0 to 1.16.0 0.8.0 v6062.0 Build 250817 Rel.23310n (excl.)
Vendor TP-Link Systems Inc.
Product XX530v(BR)v1.0
Versions Default: unaffected
  • affected from 0 to 0.6.0 3.0.0 v6096.0 Build 250416 Rel.26048n (excl.)
Vendor TP-Link Systems Inc.
Product XX530v(BR)v2.0
Versions Default: unaffected
  • affected from 0 to 0.4.0 3.1.10 v60dc.0 Build 250520 Rel.69748n (excl.)
Vendor TP-Link Systems Inc.
Product XX530v(US1)
Versions Default: unaffected
  • affected from 0 to 0.6.0 3.0.0 v6096.0 Build 250416 Rel.26048n (excl.)
Vendor TP-Link Systems Inc.
Product XX530v(EU1)
Versions Default: unaffected
  • affected from 0 to 0.3.0 3.1.10 v6107.0 Build 250425 Rel.71973n (excl.)
Vendor TP-Link Systems Inc.
Product VX800v(DE) V1.0
Versions Default: unaffected
  • affected from 0 to 800.0.16 (excl.)
Vendor TP-Link Systems Inc.
Product VX1800v(EU1) V1.0
Versions Default: unaffected
  • affected from 0 to 0.14.0 2.0.0 v6092.0 Build 250417 Rel.24761n (excl.)
Vendor TP-Link Systems Inc.
Product VX420-G2h(AU) V3.0
Versions Default: unaffected
  • affected from 0 to 0.2.0 2.0.0 v60df.0 Build 250427 Rel.38233n (excl.)

Credits

  • Gerhard Hechenberger, Stefan Schweighofer, Constantin Schieber-Knoebl from the SEC Consult Vulnerability Lab finder

References

Problem Types

  • CWE-59: Improper Link Resolution Before File Access CWE

Impacts

  • CAPEC-132: Symlink Attack