What is CVE-2025-30240?
CVE-2025-30240 is a vulnerability in TP-Link Aginet devices where symbolic links on external USB storage are not properly validated. An attacker can craft a symbolic link to cause the system to resolve it, potentially gaining unauthorized read access. Applying the manufacturer's security update is recommended.
Azərbaycanca: CVE-2025-30240 TP-Link Aginet cihazlarında xarici USB yaddaş qurğularında yaradılmış symbolic link-lərin düzgün yoxlanılmaması zəifliyidir. Təcavüzkar hazırlanmış symbolic link vasitəsilə sistemin linki izləməsinə səbəb olaraq icazəsiz oxuma girişi əldə edə bilər. İstehsalçı tərəfindən buraxılmış təhlükəsizlik yeniləməsinin tətbiq edilməsi tövsiyə olunur.
Related CVEs
link basis: shared vendor: TP-Link
FAQ1
What type of threat does CVE-2025-30240 pose in TP-Link Aginet devices?
The CVE-2025-30240 vulnerability allows an attacker to craft a symbolic link on external USB storage that causes the system to resolve it due to improper validation, potentially gaining unauthorized read access.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.