CVE-2025-30240: TP-Link Systems Inc EB810VEU1 v1.0
Medium severity, CVSS 5.1. EPSS: 0.2% chance of exploitation in the next 30 days.
The affected TP-Link Aginet devices do not properly validate symbolic links created on external USB storage devices. By placing a crafted symbolic link on supported storage media, an attacker may cause the system to resolve the link. Successful exploitation may allow unauthorized read access to sensitive files within the device filesystem.
Affected products
- TP-Link Systems Inc EB810VEU1 v1.0
- TP-Link Systems Inc EX220BR v1.0/1.20/1.28/1.29/1.8
- TP-Link Systems Inc EX220BR v2.0
- TP-Link Systems Inc EX220EU1 v1.0/1.20
- TP-Link Systems Inc EX220RU v1.0
- TP-Link Systems Inc EX220US1 v1.0
- TP-Link Systems Inc EX222EU1 v1.0
- TP-Link Systems Inc EX222KR v1.0
- TP-Link Systems Inc EX222US1 v1.0
- TP-Link Systems Inc EX520VEU11.0
- TP-Link Systems Inc EX820VEU1 v1.0
- TP-Link Systems Inc EX920US2 v1.6/v1.0
- TP-Link Systems Inc HB210 PROEU11.0
- TP-Link Systems Inc HB210 PROUS21.0/1.6
- TP-Link Systems Inc HB210EU1 1.0
- TP-Link Systems Inc HB210US2 1.0
- TP-Link Systems Inc HB410 EU1 1.0
- TP-Link Systems Inc HB610CA v2.0
- TP-Link Systems Inc HB610EU1
- TP-Link Systems Inc HB610US2 v2.6/2.0
- TP-Link Systems Inc HB710EU1 1.0
- TP-Link Systems Inc HB710US2 v1.6/1.0
- TP-Link Systems Inc HB810EU1 v2.0
- TP-Link Systems Inc HB810US2 v1.0/1.6/2.0/2.6
- TP-Link Systems Inc VX1800VEU1 v1.0
- and 8 more
Published 2026-08-10. Last modified 2026-09-29.