---
id: CVE-2025-30239
title: |-
  In affected TP-Link Aginet devices, use of
  hardcoded cryptographic keys embedded in the firmware to protect sensitive
  configuration data may allow an attacker who has access to device storage to
  recover the keys and decrypt stored data.
  …
summary: |-
  In affected TP-Link Aginet devices, use of
  hardcoded cryptographic keys embedded in the firmware to protect sensitive
  configuration data may allow an attacker who has access to device storage to
  recover the keys and decrypt stored data.
  …
severity: none
cwe:
  - CWE-321
published: '2026-08-10'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T11:10:00.150'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-30239'
references:
  - url: 'https://www.tp-link.com/us/support/faq/5239/'
    label: f23511db-6c3e-4e32-a477-6aa17d310630
tags:
  - nvd
ingestedAt: '2026-09-29T11:32:41.226Z'
---

## Overview

In affected TP-Link Aginet devices, use of
hardcoded cryptographic keys embedded in the firmware to protect sensitive
configuration data may allow an attacker who has access to device storage to
recover the keys and decrypt stored data.





Successful
exploitation may allow access to decrypted sensitive configuration data,
including credentials and service-related information.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
