VulnerabilityAwaiting Analysis
CVE-2025-30240
By placing a crafted symbolic link on supported storage media, an attacker may cause the system to resolve the link.
MEDIUM 5.1EPSS 0.18%
Does this matter?
Lower severity and a low EPSS score (0.18%). Track it; it rarely justifies an emergency change on its own.
Description
The affected TP-Link Aginet devices do not properly validate symbolic links created on external USB storage devices. By placing a crafted symbolic link on supported storage media, an attacker may cause the system to resolve the link. Successful exploitation may allow unauthorized read access to sensitive files within the device filesystem.
- CVSS 4.0
- 5.1 MEDIUMCVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.18% probability · 8th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-59
- Source
- f23511db-6c3e-4e32-a477-6aa17d310630
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.