In affected TP-Link Aginet devices, use of
hardcoded cryptographic keys embedded in the firmware to protect sensitive
configuration data may allow an attacker who has access to device storage to
recover the keys and decrypt stored data.





Successful
exploitation may allow access to decrypted sensitive configuration data,
including credentials and service-related information.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 11 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Tp-link
Tp-link eb210 Pro(eu1) 1.0
Tp-link eb210 Pro(us1) 1.0
Tp-link eb810v(eu1) V1.0
Tp-link ec220-g5(br) V3.0
Tp-link ec220-g5(eu1) V3.0
Tp-link ec220-g5(us1) V3.0
Tp-link ec225-g5(br) V1.0
Tp-link ec225-g5(eu1) V1.0
Tp-link ec225-g5(us1) V1.0
Tp-link ex141(br) V1.0/1.9
Tp-link ex141(eu1) V1.0
Tp-link ex141(us1) V1.0
Tp-link ex220(br) V1.0/1.20/1.28/1.29/1.8
Tp-link ex220(br) V2.0
Tp-link ex220(eu1) V1.0/1.20
Tp-link ex220(ru) V1.0
Tp-link ex220(us1) V1.0
Tp-link ex222(eu1) V1.0
Tp-link ex222(kr) V1.0
Tp-link ex222(us1) V1.0
Tp-link ex511(br) V2.0/2.8/2.9
Tp-link ex511(eu1) V2.0
Tp-link ex511(us1) V2.0
Tp-link ex520(us1) V1.0
Tp-link ex520v(eu1)1.0
Tp-link ex521(us1) V1.0
Tp-link ex820v(eu1) V1.0
Tp-link ex920(us2) V1.6/v1.0
Tp-link hb210(eu1) 1.0
Tp-link hb210(us2) 1.0
Tp-link hb210 Pro(eu1)1.0
Tp-link hb210 Pro(us2)1.0/1.6
Tp-link hb410( Eu1) 1.0
Tp-link hb610(ca) V2.0
Tp-link hb610(eu1)
Tp-link hb610(us2) V2.6/2.0
Tp-link hb710(eu1) 1.0
Tp-link hb710(us2) V1.6/1.0
Tp-link hb810(eu1) V2.0
Tp-link hb810(us2) V1.0/1.6/2.0/2.6
Tp-link hc220-g5(br) V1.30
Tp-link hc220-g5(eu1) V1.20/1.0
Tp-link hc220-g5(us1) V1.0/1.6
Tp-link hx141(eu1) V1.0
Tp-link hx220(au) V1.0
Tp-link hx220(ca) V1.0
Tp-link hx220(eu1) V1.0
Tp-link hx220(us1) V1.0/1.0
Tp-link hx510(au) V1.0/2.0
Tp-link hx510(ca) V1.0/2.0
Tp-link hx510(eu1) V2.0
Tp-link hx510(us1) V2.0
Tp-link hx510(us2) 2.6
Tp-link hx710(eu1) V1.0
Tp-link hx710 Pro(eu1) V1.0
Tp-link vx1800v(eu1) V1.0
Tp-link vx420-g2h(au) V3.0
Tp-link vx800v(de) V1.0
Tp-link xc220-g3v(eu1) V2.30
Tp-link xc220-g3v(us1) V2.30
Tp-link xx230v(br) V1.0
Tp-link xx530v(br)v1.0
Tp-link xx530v(br)v2.0
Tp-link xx530v(eu1)
Tp-link xx530v(us1)
Vendors & Products Tp-link
Tp-link eb210 Pro(eu1) 1.0
Tp-link eb210 Pro(us1) 1.0
Tp-link eb810v(eu1) V1.0
Tp-link ec220-g5(br) V3.0
Tp-link ec220-g5(eu1) V3.0
Tp-link ec220-g5(us1) V3.0
Tp-link ec225-g5(br) V1.0
Tp-link ec225-g5(eu1) V1.0
Tp-link ec225-g5(us1) V1.0
Tp-link ex141(br) V1.0/1.9
Tp-link ex141(eu1) V1.0
Tp-link ex141(us1) V1.0
Tp-link ex220(br) V1.0/1.20/1.28/1.29/1.8
Tp-link ex220(br) V2.0
Tp-link ex220(eu1) V1.0/1.20
Tp-link ex220(ru) V1.0
Tp-link ex220(us1) V1.0
Tp-link ex222(eu1) V1.0
Tp-link ex222(kr) V1.0
Tp-link ex222(us1) V1.0
Tp-link ex511(br) V2.0/2.8/2.9
Tp-link ex511(eu1) V2.0
Tp-link ex511(us1) V2.0
Tp-link ex520(us1) V1.0
Tp-link ex520v(eu1)1.0
Tp-link ex521(us1) V1.0
Tp-link ex820v(eu1) V1.0
Tp-link ex920(us2) V1.6/v1.0
Tp-link hb210(eu1) 1.0
Tp-link hb210(us2) 1.0
Tp-link hb210 Pro(eu1)1.0
Tp-link hb210 Pro(us2)1.0/1.6
Tp-link hb410( Eu1) 1.0
Tp-link hb610(ca) V2.0
Tp-link hb610(eu1)
Tp-link hb610(us2) V2.6/2.0
Tp-link hb710(eu1) 1.0
Tp-link hb710(us2) V1.6/1.0
Tp-link hb810(eu1) V2.0
Tp-link hb810(us2) V1.0/1.6/2.0/2.6
Tp-link hc220-g5(br) V1.30
Tp-link hc220-g5(eu1) V1.20/1.0
Tp-link hc220-g5(us1) V1.0/1.6
Tp-link hx141(eu1) V1.0
Tp-link hx220(au) V1.0
Tp-link hx220(ca) V1.0
Tp-link hx220(eu1) V1.0
Tp-link hx220(us1) V1.0/1.0
Tp-link hx510(au) V1.0/2.0
Tp-link hx510(ca) V1.0/2.0
Tp-link hx510(eu1) V2.0
Tp-link hx510(us1) V2.0
Tp-link hx510(us2) 2.6
Tp-link hx710(eu1) V1.0
Tp-link hx710 Pro(eu1) V1.0
Tp-link vx1800v(eu1) V1.0
Tp-link vx420-g2h(au) V3.0
Tp-link vx800v(de) V1.0
Tp-link xc220-g3v(eu1) V2.30
Tp-link xc220-g3v(us1) V2.30
Tp-link xx230v(br) V1.0
Tp-link xx530v(br)v1.0
Tp-link xx530v(br)v2.0
Tp-link xx530v(eu1)
Tp-link xx530v(us1)

Tue, 11 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 10 Aug 2026 22:45:00 +0000

Type Values Removed Values Added
Description In affected TP-Link Aginet devices, use of hardcoded cryptographic keys embedded in the firmware to protect sensitive configuration data may allow an attacker who has access to device storage to recover the keys and decrypt stored data. Successful exploitation may allow access to decrypted sensitive configuration data, including credentials and service-related information.
Title Sensitive Data Exposure due to Hardcoded Cryptographic Keys in Multiple TP-Link Aginet Devices
Weaknesses CWE-321
References
Metrics cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: TPLink

Published:

Updated: 2026-08-11T14:49:10.875Z

Reserved: 2025-03-19T11:09:33.244Z

Link: CVE-2025-30239

cve-icon Vulnrichment

Updated: 2026-08-11T14:49:07.565Z

cve-icon NVD

Status : Received

Published: 2026-08-10T23:16:50.173

Modified: 2026-08-11T15:17:25.380

Link: CVE-2025-30239

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-11T14:21:27Z

Weaknesses