CVE-2025-30239
Received Received - Intake

Hardcoded Cryptographic Key in TP-Link Aginet Devices

Vulnerability report for CVE-2025-30239, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-10

Last updated on: 2026-08-10

Assigner: TPLink

Description

In affected TP-Link Aginet devices, use of hardcoded cryptographic keys embedded in the firmware to protect sensitive configuration data may allow an attacker who has access to device storage to recover the keys and decrypt stored data. Successful exploitation may allow access to decrypted sensitive configuration data, including credentials and service-related information.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-10
Last Modified
2026-08-10
Generated
2026-08-11
AI Q&A
2026-08-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
tp-link aginet *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-321 The product uses a hard-coded, unchangeable cryptographic key.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves TP-Link Aginet devices using hardcoded cryptographic keys in firmware to protect sensitive configuration data. An attacker with access to device storage could extract these keys and decrypt the stored data, potentially exposing credentials and service-related information.

Detection Guidance

Detection of this vulnerability requires checking for hardcoded cryptographic keys in TP-Link Aginet device firmware. Inspect device storage and firmware images for embedded keys using tools like strings, binwalk, or firmware analysis tools. No specific commands are provided in the context.

Impact Analysis

An attacker could gain access to sensitive configuration data, including credentials and service details, by decrypting stored information. This may lead to unauthorized access to network services or devices managed by the affected TP-Link Aginet system.

Mitigation Strategies

Immediate mitigation steps include updating TP-Link Aginet devices to the latest firmware version if available, isolating affected devices from sensitive networks, and replacing devices if updates are not provided. Monitor TP-Link advisories for patches.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-30239. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart