Medium severityNVD Advisory· Published Aug 10, 2026· Updated Aug 18, 2026
CVE-2025-30240
CVE-2025-30240
Description
The affected TP-Link Aginet devices do not properly validate symbolic links created on external USB storage devices. By placing a crafted symbolic link on supported storage media, an attacker may cause the system to resolve the link.
Successful exploitation may allow unauthorized read access to sensitive files within the device filesystem.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
1News mentions
1- Multiple TP-Link Vulnerabilities Allow Attackers to Bypass Authentication and Escalate PrivilegesCyber Security News · Aug 14, 2026