Junglewise Threat Intelligence

CVE-2025-30240: TP-Link Aginet symbolic link validation bypass on USB storage

CVE-2025-30240 · Severity: info · CVSS 5.1 · Published 2026-08-10

Vendors: TP-Link.

Executive brief

TP-Link Aginet mesh networking devices used by ISPs and service providers fail to properly validate symbolic links on external USB storage. An attacker with physical access to a USB port can craft a malicious symlink to read sensitive system files, potentially exposing credentials and configuration data stored on the device.

Technical details

This vulnerability is a symlink traversal issue (CWE-59) affecting the USB file access path in TP-Link Aginet devices. The web interface does not validate or sanitize symbolic links placed on external USB storage media before resolving them, allowing path traversal attacks. An attacker with physical access to a USB port can create a symbolic link pointing to sensitive files in the device filesystem and then access those files through the web interface's USB file browser. Successful exploitation grants unauthorized read access to sensitive files including credentials and service-related configuration data. The vulnerability requires physical access to insert a crafted USB device and is rated CVSS 5.1 (Medium). Patches are available in the fix versions listed in the advisory.

Affected products

  • TP-Link Aginet HB Series HB810(US2) V1.0/1.6/2.0/2.6; HB810(EU1) V2.0; HB710(US2) V1.6/1.0; HB710(EU1) 1.0; HB610(US2) V2.6/2.0; HB610(EU1); HB610(CA) V2.0; HB410(EU1) 1.0; HB210(US2) 1.0; HB210(EU1) 1.0; HB210 Pro(EU1) 1.0; HB210 Pro(US2) 1.0/1.6
  • TP-Link Aginet HX Series HX510(US1) V2.0; HX510(EU1) V2.0; HX510(CA) V1.0/2.0; HX510(AU) V1.0/2.0; HX510(US2) 2.6; HX710(EU1) V1.0; HX710 Pro(EU1) V1.0; HX220(US1) V1.0; HX220(EU1) V1.0; HX220(CA) V1.0; HX220(AU) V1.0

Timeline

  • 2026-08-10: disclosed: CVE-2025-30240 published in security advisory

References