CVE-2025-30240
Severity CVSS v4.0:
MEDIUM
Type:
CWE-59
Link Following
Publication date:
10/08/2026
Last modified:
10/08/2026
Description
The affected TP-Link Aginet devices do not properly validate symbolic links created on external USB storage<br />
devices. By placing a crafted symbolic link on supported storage media, an<br />
attacker may cause the system to resolve the link.<br />
<br />
<br />
<br />
<br />
<br />
<br />
<br />
<br />
<br />
Successful<br />
exploitation may allow unauthorized read access to sensitive files within the<br />
device filesystem.
Impact
Base Score 4.0
5.10
Severity 4.0
MEDIUM



