CVE-2025-30239

HIGHCVSS 8.5/10EPSS 0.14%

Last modified

CVE-2025-30239 is a high-severity vulnerability rated 8.5/10 on the CVSS scale. In affected TP-Link Aginet devices, use of hardcoded cryptographic keys embedded in the firmware to protect sensitive configuration data may allow an attacker who has access to device storage to recover the keys and decrypt stored data. Successful exploitation may allow access to decrypted sensitive configuration data, including credentials and service-related information.. EPSS estimates a 0.14% chance of exploitation in the next 30 days.

Description

In affected TP-Link Aginet devices, use of hardcoded cryptographic keys embedded in the firmware to protect sensitive configuration data may allow an attacker who has access to device storage to recover the keys and decrypt stored data. Successful exploitation may allow access to decrypted sensitive configuration data, including credentials and service-related information.

Metrics

CVSS 4.0
8.5/10

CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

EPSS Probability
0.14%

3.3th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
TP-Link Systems Inc.HB810(US2) V1.0/1.6/2.0/2.6< 0.9.0 3.2.2 v6095.0 Build 260717 Rel.67188n
TP-Link Systems Inc.HB810(EU1) V2.0< 0.10.0 3.2.2 v6095.0 Build 260306 Rel.47567n
TP-Link Systems Inc.HB710(US2) V1.6/1.0< 0.3.0 3.0.0 v60be.0 Build 251128 Rel.43956n
TP-Link Systems Inc.HB710(EU1) 1.0< 0.3.0 3.0.0 v60be.0 Build 251128 Rel.43956n
TP-Link Systems Inc.HB610(US2) V2.6/2.0< 0.6.0 3.0.0 v60af.0 Build 251204 Rel.20362n
TP-Link Systems Inc.HB610(EU1)< 0.6.0 3.0.0 v60af.0 Build 251204 Rel.20362n
TP-Link Systems Inc.HB610(CA) V2.0< 0.6.0 3.0.0 v60af.0 Build 251216 Rel.46954n
TP-Link Systems Inc.HB410( EU1) 1.0< 0.3.0 3.0.0 v60bf.0 Build 250901 Rel.45574n
TP-Link Systems Inc.HB210(US2) 1.0< 0.2.0 3.0.0 v60f9.0 Build 250826 Rel.47715n
TP-Link Systems Inc.HB210(EU1) 1.0< 0.2.0 3.0.0 v60f9.0 Build 250826 Rel.47715n
TP-Link Systems Inc.HB210 Pro(EU1)1.0< 0.5.0 3.0.0 v60d5.0 Build 250922 Rel.13742n
TP-Link Systems Inc.HB210 Pro(US2)1.0/1.6< 0.8.0 3.0.0 v60d5.0 Build 260318 Rel.78363n
TP-Link Systems Inc.HX510(US1) V2.0< 0.14.0 3.0.0 v6065.0 Build 250822 Rel.81150n
TP-Link Systems Inc.HX510(EU1) V2.0< 0.14.0 3.0.0 v6065.0 Build 250822 Rel.81150n
TP-Link Systems Inc.HX510(CA) V1.0/2.0< 0.14.0 3.0.0 v6065.0 Build 250822 Rel.81150n
TP-Link Systems Inc.HX510(AU) V1.0/2.0< 0.14.0 3.0.0 v6065.0 Build 250822 Rel.81150n
TP-Link Systems Inc.HX510(US2) 2.6< 0.17.0 3.2.2 v6065.0 Build 260722 Rel.10662n
TP-Link Systems Inc.HX710(EU1) V1.0< 0.5.0 3.1.10 v6075.0 Build 260511 Rel.47847n
TP-Link Systems Inc.HX710 Pro(EU1) V1.0< 0.4.0 3.1.10 v6082.0 Build 260204 Rel.49460n
TP-Link Systems Inc.HX220(US1) V1.0/1.0< 0.21.0 2.0.0 v605f.0 Build 250306 Rel.9224n
TP-Link Systems Inc.HX220(EU1) V1.0< 0.21.0 2.0.0 v605f.0 Build 250306 Rel.9224n
TP-Link Systems Inc.HX220(CA) V1.0< 0.21.0 2.0.0 v605f.0 Build 250306 Rel.9224n
TP-Link Systems Inc.HX220(AU) V1.0< 0.21.0 2.0.0 v605f.0 Build 250306 Rel.9224n
TP-Link Systems Inc.HX141(EU1) V1.0< 1.2.0 3.1.0 v609d.0 Build 260128 Rel.29711n
TP-Link Systems Inc.HC220-G5(US1) V1.0/1.6< 0.18.0 2.0.0 v605e.0 Build 250827 Rel.37904n
TP-Link Systems Inc.HC220-G5(EU1) V1.20/1.0< 0.18.0 2.0.0 v605e.0 Build 250827 Rel.37904n
TP-Link Systems Inc.HC220-G5(BR) V1.30< 0.17.0 2.0.0 v605e.0 Build 250618 Rel.19329n
TP-Link Systems Inc.EB210 Pro(EU1) 1.0< 0.2.0 3.0.0 v60f4.0 Build 250807 Rel.58901n
TP-Link Systems Inc.EB210 Pro(US1) 1.0< 0.2.0 3.0.0 v60f4.0 Build 250807 Rel.58901n
TP-Link Systems Inc.EB810v(EU1) V1.0< 0.6.0 3.0.0 v608b.0 Build 250613 Rel.10497n
TP-Link Systems Inc.EC220-G5(BR) V3.0< 1.14.1 Build 250715 Rel.72650n(4252)
TP-Link Systems Inc.EC220-G5(EU1) V3.0< 1.15.1 Build 260205 Rel.38208n(4555)
TP-Link Systems Inc.EC220-G5(US1) V3.0< 1.14.1 Build 250715 Rel.72650n(4252)
TP-Link Systems Inc.EC225-G5(BR) V1.0< 1.14.1 Build 250717 Rel.34953n(4252)
TP-Link Systems Inc.EC225-G5(EU1) V1.0< 1.14.1 Build 250711 Rel.35878n(4555)
TP-Link Systems Inc.EC225-G5(US1) V1.0< 1.1.14.1 Build 250711 Rel.35607n(5553)
TP-Link Systems Inc.EX141(BR) V1.0/1.9< 1.8.0 3.1.0 v608a.0 Build 250425 Rel.40905n
TP-Link Systems Inc.EX141(EU1) V1.0< 1.7.0 3.1.0 v608a.0 Build 250418 Rel.8257n
TP-Link Systems Inc.EX141(US1) V1.0< 1.7.0 3.1.0 v608a.0 Build 250418 Rel.8257n
TP-Link Systems Inc.EX220(BR) V1.0/1.20/1.28/1.29/1.8< 0.20.0 2.0.0 v605f.0 Build 250305 Rel.14728n
TP-Link Systems Inc.EX220(BR) V2.0< 0.19.0 2.0.0 v609b.0 Build 250814 Rel.49732n
TP-Link Systems Inc.EX220(EU1) V1.0/1.20< 0.20.0 2.0.0 v605f.0 Build 250305 Rel.14728n
TP-Link Systems Inc.EX220(RU) V1.0< 0.20.0 2.0.0 v605f.0 Build 250305 Rel.14728n
TP-Link Systems Inc.EX220(US1) V1.0< 0.20.0 2.0.0 v605f.0 Build 250305 Rel.14728n
TP-Link Systems Inc.EX222(EU1) V1.0< 0.20.0 2.0.0 v605f.0 Build 250305 Rel.14728n
TP-Link Systems Inc.EX222(KR) V1.0< 0.20.0 2.0.0 v609b.0 Build 260427 Rel.16915
TP-Link Systems Inc.EX222(US1) V1.0< 0.20.0 2.0.0 v605f.0 Build 250305 Rel.14728n
TP-Link Systems Inc.EX511(BR) V2.0/2.8/2.9< 0.9.0 3.0.0 v607e.0 Build 260520 Rel.33425n
TP-Link Systems Inc.EX511(EU1) V2.0< 0.9.0 3.0.0 v607e.0 Build 260520 Rel.33425n
TP-Link Systems Inc.EX511(US1) V2.0< 0.8.0 3.0.0 v607e.0 Build 260424 Rel.27419n

Showing 50 of 65 affected configurations. See the CNA advisory for the full list.

References

Timeline

Published
Last Modified
Status
Received

Frequently Asked Questions

What is CVE-2025-30239?
In affected TP-Link Aginet devices, use of hardcoded cryptographic keys embedded in the firmware to protect sensitive configuration data may allow an attacker who has access to device storage to recover the keys and decrypt stored data. Successful exploitation may allow access to decrypted sensitive configuration data, including credentials and service-related information.
How severe is CVE-2025-30239?
CVE-2025-30239 has a CVSS score of 8.5/10 (HIGH severity). The EPSS model estimates a 0.14% probability of exploitation in the next 30 days.
How do I fix CVE-2025-30239?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2025

Are you affected by CVE-2025-30239?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST