PatchSiren cyber security CVE debrief
CVE-2025-30239 TP-Link Systems Inc. CVE debrief
TP-Link Aginet devices use hardcoded cryptographic keys embedded in firmware, allowing attackers with device storage access to recover keys and decrypt sensitive configuration data. This vulnerability impacts confidentiality and integrity, with potential access to decrypted sensitive configuration data, including credentials and service-related information. Defenders should assess exposure, verify device storage access controls, and prioritize remediation for affected devices. The CVE record and NVD entry provide limited information on affected versions and remediation, requiring further verification.
- Vendor
- TP-Link Systems Inc.
- Product
- HB810(US2) V1.0/1.6/2.0/2.6
- CVSS
- HIGH 8.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-10
- Original CVE updated
- 2026-09-29
- Advisory published
- 2026-08-10
- Advisory updated
- 2026-09-29
Who should care
Defenders responsible for TP-Link Aginet devices, including security teams, vulnerability management teams, and operators, should assess exposure, verify device storage access controls, and prioritize remediation for affected devices. This vulnerability impacts confidentiality and integrity, with potential access to decrypted sensitive configuration data, including credentials and service-related information. Defenders should review configuration data
Why it matters
CVE-2025-30239 allows attackers with device storage access to recover hardcoded cryptographic keys and decrypt sensitive configuration data, potentially impacting confidentiality and integrity.
- Potential access to decrypted sensitive configuration data
- Possible recovery of hardcoded cryptographic keys
- Verification of device storage access controls required
- Remediation priority for affected devices
Technical summary
TP-Link Aginet devices use hardcoded cryptographic keys embedded in firmware to protect sensitive configuration data. Attackers with device storage access can recover keys and decrypt stored data, potentially gaining access to decrypted sensitive configuration data, including credentials and service-related information. This vulnerability impacts confidentiality and integrity, emphasizing the need for defenders to verify device storage access controls and prioritize remediation for affected devices. Further verification is required to assess exposure and identify potentially affected devices.
Defensive priority
Verify device storage access controls and monitor for potential key recovery attempts.
Recommended defensive actions
- Verify device storage access controls
- Monitor for potential key recovery attempts
- Review configuration data encryption
- Assess exposure of affected TP-Link Aginet devices
- Prioritize remediation for confirmed exposures
- Track exceptions and retest remediated assets
- Document evidence of verification and remediation efforts
Evidence notes
The CVE record and NVD entry provide limited information on affected versions and remediation. Further verification is required to assess exposure, identify potentially affected devices, and prioritize remediation. Defenders should review configuration data encryption, monitor for potential key recovery attempts, and verify device storage access controls. The hardcoded cryptographic keys pose a significant risk to confidentiality and integrity if exploited.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-30239 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-30239
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-30239 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-30239
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://www.tp-link.com/us/support/faq/5239/
f23511db-6c3e-4e32-a477-6aa17d310630
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.