hardcoded cryptographic keys embedded in the firmware to protect sensitive
configuration data may allow an attacker who has access to device storage to
recover the keys and decrypt stored data.
Successful
exploitation may allow access to decrypted sensitive configuration data,
including credentials and service-related information.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://www.tp-link.com/us/support/faq/5239/ |
|
Tue, 11 Aug 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tp-link
Tp-link eb210 Pro(eu1) 1.0 Tp-link eb210 Pro(us1) 1.0 Tp-link eb810v(eu1) V1.0 Tp-link ec220-g5(br) V3.0 Tp-link ec220-g5(eu1) V3.0 Tp-link ec220-g5(us1) V3.0 Tp-link ec225-g5(br) V1.0 Tp-link ec225-g5(eu1) V1.0 Tp-link ec225-g5(us1) V1.0 Tp-link ex141(br) V1.0/1.9 Tp-link ex141(eu1) V1.0 Tp-link ex141(us1) V1.0 Tp-link ex220(br) V1.0/1.20/1.28/1.29/1.8 Tp-link ex220(br) V2.0 Tp-link ex220(eu1) V1.0/1.20 Tp-link ex220(ru) V1.0 Tp-link ex220(us1) V1.0 Tp-link ex222(eu1) V1.0 Tp-link ex222(kr) V1.0 Tp-link ex222(us1) V1.0 Tp-link ex511(br) V2.0/2.8/2.9 Tp-link ex511(eu1) V2.0 Tp-link ex511(us1) V2.0 Tp-link ex520(us1) V1.0 Tp-link ex520v(eu1)1.0 Tp-link ex521(us1) V1.0 Tp-link ex820v(eu1) V1.0 Tp-link ex920(us2) V1.6/v1.0 Tp-link hb210(eu1) 1.0 Tp-link hb210(us2) 1.0 Tp-link hb210 Pro(eu1)1.0 Tp-link hb210 Pro(us2)1.0/1.6 Tp-link hb410( Eu1) 1.0 Tp-link hb610(ca) V2.0 Tp-link hb610(eu1) Tp-link hb610(us2) V2.6/2.0 Tp-link hb710(eu1) 1.0 Tp-link hb710(us2) V1.6/1.0 Tp-link hb810(eu1) V2.0 Tp-link hb810(us2) V1.0/1.6/2.0/2.6 Tp-link hc220-g5(br) V1.30 Tp-link hc220-g5(eu1) V1.20/1.0 Tp-link hc220-g5(us1) V1.0/1.6 Tp-link hx141(eu1) V1.0 Tp-link hx220(au) V1.0 Tp-link hx220(ca) V1.0 Tp-link hx220(eu1) V1.0 Tp-link hx220(us1) V1.0/1.0 Tp-link hx510(au) V1.0/2.0 Tp-link hx510(ca) V1.0/2.0 Tp-link hx510(eu1) V2.0 Tp-link hx510(us1) V2.0 Tp-link hx510(us2) 2.6 Tp-link hx710(eu1) V1.0 Tp-link hx710 Pro(eu1) V1.0 Tp-link vx1800v(eu1) V1.0 Tp-link vx420-g2h(au) V3.0 Tp-link vx800v(de) V1.0 Tp-link xc220-g3v(eu1) V2.30 Tp-link xc220-g3v(us1) V2.30 Tp-link xx230v(br) V1.0 Tp-link xx530v(br)v1.0 Tp-link xx530v(br)v2.0 Tp-link xx530v(eu1) Tp-link xx530v(us1) |
|
| Vendors & Products |
Tp-link
Tp-link eb210 Pro(eu1) 1.0 Tp-link eb210 Pro(us1) 1.0 Tp-link eb810v(eu1) V1.0 Tp-link ec220-g5(br) V3.0 Tp-link ec220-g5(eu1) V3.0 Tp-link ec220-g5(us1) V3.0 Tp-link ec225-g5(br) V1.0 Tp-link ec225-g5(eu1) V1.0 Tp-link ec225-g5(us1) V1.0 Tp-link ex141(br) V1.0/1.9 Tp-link ex141(eu1) V1.0 Tp-link ex141(us1) V1.0 Tp-link ex220(br) V1.0/1.20/1.28/1.29/1.8 Tp-link ex220(br) V2.0 Tp-link ex220(eu1) V1.0/1.20 Tp-link ex220(ru) V1.0 Tp-link ex220(us1) V1.0 Tp-link ex222(eu1) V1.0 Tp-link ex222(kr) V1.0 Tp-link ex222(us1) V1.0 Tp-link ex511(br) V2.0/2.8/2.9 Tp-link ex511(eu1) V2.0 Tp-link ex511(us1) V2.0 Tp-link ex520(us1) V1.0 Tp-link ex520v(eu1)1.0 Tp-link ex521(us1) V1.0 Tp-link ex820v(eu1) V1.0 Tp-link ex920(us2) V1.6/v1.0 Tp-link hb210(eu1) 1.0 Tp-link hb210(us2) 1.0 Tp-link hb210 Pro(eu1)1.0 Tp-link hb210 Pro(us2)1.0/1.6 Tp-link hb410( Eu1) 1.0 Tp-link hb610(ca) V2.0 Tp-link hb610(eu1) Tp-link hb610(us2) V2.6/2.0 Tp-link hb710(eu1) 1.0 Tp-link hb710(us2) V1.6/1.0 Tp-link hb810(eu1) V2.0 Tp-link hb810(us2) V1.0/1.6/2.0/2.6 Tp-link hc220-g5(br) V1.30 Tp-link hc220-g5(eu1) V1.20/1.0 Tp-link hc220-g5(us1) V1.0/1.6 Tp-link hx141(eu1) V1.0 Tp-link hx220(au) V1.0 Tp-link hx220(ca) V1.0 Tp-link hx220(eu1) V1.0 Tp-link hx220(us1) V1.0/1.0 Tp-link hx510(au) V1.0/2.0 Tp-link hx510(ca) V1.0/2.0 Tp-link hx510(eu1) V2.0 Tp-link hx510(us1) V2.0 Tp-link hx510(us2) 2.6 Tp-link hx710(eu1) V1.0 Tp-link hx710 Pro(eu1) V1.0 Tp-link vx1800v(eu1) V1.0 Tp-link vx420-g2h(au) V3.0 Tp-link vx800v(de) V1.0 Tp-link xc220-g3v(eu1) V2.30 Tp-link xc220-g3v(us1) V2.30 Tp-link xx230v(br) V1.0 Tp-link xx530v(br)v1.0 Tp-link xx530v(br)v2.0 Tp-link xx530v(eu1) Tp-link xx530v(us1) |
Tue, 11 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 10 Aug 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In affected TP-Link Aginet devices, use of hardcoded cryptographic keys embedded in the firmware to protect sensitive configuration data may allow an attacker who has access to device storage to recover the keys and decrypt stored data. Successful exploitation may allow access to decrypted sensitive configuration data, including credentials and service-related information. | |
| Title | Sensitive Data Exposure due to Hardcoded Cryptographic Keys in Multiple TP-Link Aginet Devices | |
| Weaknesses | CWE-321 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
Status: PUBLISHED
Assigner: TPLink
Published:
Updated: 2026-08-11T14:49:10.875Z
Reserved: 2025-03-19T11:09:33.244Z
Link: CVE-2025-30239
Updated: 2026-08-11T14:49:07.565Z
Status : Received
Published: 2026-08-10T23:16:50.173
Modified: 2026-08-11T15:17:25.380
Link: CVE-2025-30239
No data.
OpenCVE Enrichment
Updated: 2026-08-11T14:21:27Z
-
CWE-321
Use of Hard-coded Cryptographic Key