CVE-2025-15541
Unknown
Unknown - Not Provided
Improper Link Resolution in VX800v SFTP Causes Data Exposure
Publication date: 2026-01-29
Last updated on: 2026-03-09
Assigner: TPLink
Description
Description
Improper link resolution in the VX800v v1.0 SFTP service allows authenticated adjacent attackers to use crafted symbolic links to access system files, resulting in high confidentiality impact and limited integrity risk.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| tp-link | vx800v_firmware | to 800.0.11 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-59 | The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource. |