CVE-2025-15543: TP-Link VX800V Firmware

Medium severity, CVSS 4.6. EPSS: 0.2% chance of exploitation in the next 30 days.

Improper link resolution in USB HTTP access path in VX800v v1.0 allows a crafted USB device to expose root filesystem contents, giving an attacker with physical access read‑only access to system files.

Affected products

  • TP-Link VX800V Firmware: before 800.0.11 (fixed in 800.0.11)

Published 2026-01-29. Last modified 2026-06-17.