PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-30239 TP-Link Systems Inc. CVE debrief

TP-Link Aginet devices use hardcoded cryptographic keys embedded in firmware, allowing attackers with device storage access to recover keys and decrypt sensitive configuration data. This vulnerability impacts confidentiality and integrity, with potential access to decrypted sensitive configuration data, including credentials and service-related information. Defenders should assess exposure, verify device storage access controls, and prioritize remediation for affected devices. The CVE record and NVD entry provide limited information on affected versions and remediation, requiring further verification.

Vendor
TP-Link Systems Inc.
Product
HB810(US2) V1.0/1.6/2.0/2.6
CVSS
HIGH 8.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-10
Original CVE updated
2026-09-29
Advisory published
2026-08-10
Advisory updated
2026-09-29

Who should care

Defenders responsible for TP-Link Aginet devices, including security teams, vulnerability management teams, and operators, should assess exposure, verify device storage access controls, and prioritize remediation for affected devices. This vulnerability impacts confidentiality and integrity, with potential access to decrypted sensitive configuration data, including credentials and service-related information. Defenders should review configuration data

Why it matters

CVE-2025-30239 allows attackers with device storage access to recover hardcoded cryptographic keys and decrypt sensitive configuration data, potentially impacting confidentiality and integrity.

  • Potential access to decrypted sensitive configuration data
  • Possible recovery of hardcoded cryptographic keys
  • Verification of device storage access controls required
  • Remediation priority for affected devices

Technical summary

TP-Link Aginet devices use hardcoded cryptographic keys embedded in firmware to protect sensitive configuration data. Attackers with device storage access can recover keys and decrypt stored data, potentially gaining access to decrypted sensitive configuration data, including credentials and service-related information. This vulnerability impacts confidentiality and integrity, emphasizing the need for defenders to verify device storage access controls and prioritize remediation for affected devices. Further verification is required to assess exposure and identify potentially affected devices.

Defensive priority

Verify device storage access controls and monitor for potential key recovery attempts.

Recommended defensive actions

  • Verify device storage access controls
  • Monitor for potential key recovery attempts
  • Review configuration data encryption
  • Assess exposure of affected TP-Link Aginet devices
  • Prioritize remediation for confirmed exposures
  • Track exceptions and retest remediated assets
  • Document evidence of verification and remediation efforts

Evidence notes

The CVE record and NVD entry provide limited information on affected versions and remediation. Further verification is required to assess exposure, identify potentially affected devices, and prioritize remediation. Defenders should review configuration data encryption, monitor for potential key recovery attempts, and verify device storage access controls. The hardcoded cryptographic keys pose a significant risk to confidentiality and integrity if exploited.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-30239 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-30239

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-30239 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-30239

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://www.tp-link.com/us/support/faq/5239/

    f23511db-6c3e-4e32-a477-6aa17d310630

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.