CVE-2025-30240: Arbitrary File Read via Improper Symlink Handling in USB HTTPS Access Path in multiple TP-Link Aginet Devices
The affected TP-Link Aginet devices do not properly validate symbolic links created on external USB storage devices. By placing a crafted symbolic link on supported storage media, an attacker may cause the system to resolve the link.
Successful exploitation may allow unauthorized read access to sensitive files within the device filesystem.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-30240?
The severity of CVE-2025-30240 is rated as 47, indicating a significant security risk.
How do I fix CVE-2025-30240?
To mitigate CVE-2025-30240, ensure that your TP-Link Aginet devices have the latest firmware updates applied.
Which TP-Link devices are affected by CVE-2025-30240?
CVE-2025-30240 affects multiple TP-Link Aginet devices that use external USB storage.
What type of attack does CVE-2025-30240 facilitate?
CVE-2025-30240 allows an attacker to perform arbitrary file read operations through improper symlink handling.
Is user interaction required to exploit CVE-2025-30240?
No, CVE-2025-30240 can be exploited without user interaction by placing a crafted symlink on the USB device.