---
id: CVE-2025-30240
title: >-
  The affected TP-Link Aginet devices do not properly validate symbolic links
  created on external USB storage

  devices
summary: >-
  The affected TP-Link Aginet devices do not properly validate symbolic links
  created on external USB storage

  devices. By placing a crafted symbolic link on supported storage media, an

  attacker may cause the system to resolve the link.




  …
severity: none
cwe:
  - CWE-59
published: '2026-08-10'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T11:10:00.150'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-30240'
references:
  - url: 'https://www.tp-link.com/us/support/faq/5239/'
    label: f23511db-6c3e-4e32-a477-6aa17d310630
tags:
  - nvd
ingestedAt: '2026-09-29T11:32:41.226Z'
epss: 0.00232
epssPercentile: 0.12693
---

## Overview

The affected TP-Link Aginet devices do not properly validate symbolic links created on external USB storage
devices. By placing a crafted symbolic link on supported storage media, an
attacker may cause the system to resolve the link.









Successful
exploitation may allow unauthorized read access to sensitive files within the
device filesystem.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
