In affected TP-Link Aginet devices, use of
hardcoded cryptographic keys embedded in the firmware to protect sensitive
configuration data may allow an attacker who has access to device storage to
recover the keys and decrypt stored data.
Successful
exploitation may allow access to decrypted sensitive configuration data,
including credentials and service-related information.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.tp-link.com/us/support/faq/5239/ |
|
History
Mon, 10 Aug 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In affected TP-Link Aginet devices, use of hardcoded cryptographic keys embedded in the firmware to protect sensitive configuration data may allow an attacker who has access to device storage to recover the keys and decrypt stored data. Successful exploitation may allow access to decrypted sensitive configuration data, including credentials and service-related information. | |
| Title | Sensitive Data Exposure due to Hardcoded Cryptographic Keys in Multiple TP-Link Aginet Devices | |
| Weaknesses | CWE-321 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: TPLink
Published:
Updated: 2026-08-10T22:25:03.690Z
Reserved: 2025-03-19T11:09:33.244Z
Link: CVE-2025-30239
No data.
No data.
No data.
OpenCVE Enrichment
No data.