Executive brief
TP-Link Aginet networking devices use hardcoded cryptographic keys embedded in the firmware to protect sensitive configuration data. An attacker with access to device storage can extract these keys and decrypt stored sensitive information, including administrative credentials and service details. This could allow unauthorized access to device configuration and management systems.
Technical details
The vulnerability is a use of hardcoded cryptographic keys stored in device firmware to encrypt sensitive configuration data. An attacker who gains access to device storage (either through adjacent network access with low privileges or physical access) can extract the hardcoded keys from the firmware and use them to decrypt stored configuration data. The attack requires either prior device access with low-level privileges or physical/storage-level access to retrieve the keys and encrypted data. Successful exploitation exposes decrypted credentials, service configuration, and other sensitive administrative information. Patches are available for affected Aginet mesh series devices (HB and HX series).
Affected products
- TP-Link Aginet HB810 V1.0, V1.6, V2.0, V2.6
- TP-Link Aginet HB710 V1.0, V1.6
- TP-Link Aginet HB610 V2.0, V2.6
- TP-Link Aginet HB410 V1.0
- TP-Link Aginet HB210 V1.0
- TP-Link Aginet HB210 Pro V1.0, V1.6
- TP-Link Aginet HX510 V1.0, V2.0, V2.6
- TP-Link Aginet HX710 V1.0
- TP-Link Aginet HX710 Pro V1.0
- TP-Link Aginet HX220 V1.0
Timeline
- 2026-08-10: disclosed
- 2026-08-10: advisory