Improper link resolution in the VX800v v1.0 SFTP service allows authenticated adjacent attackers to use crafted symbolic links to access system files, resulting in high confidentiality impact and limited integrity risk.
History

Fri, 30 Jan 2026 09:00:00 +0000

Type Values Removed Values Added
First Time appeared Tp-link
Tp-link vx800v
Vendors & Products Tp-link
Tp-link vx800v

Thu, 29 Jan 2026 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 29 Jan 2026 18:30:00 +0000

Type Values Removed Values Added
Description Improper link resolution in the VX800v v1.0 SFTP service allows authenticated adjacent attackers to use crafted symbolic links to access system files, resulting in high confidentiality impact and limited integrity risk.
Title Access to System Files via SFTP on TP-Link VX800v
Weaknesses CWE-59
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: TPLink

Published: 2026-01-29T18:05:57.407Z

Updated: 2026-01-29T20:37:28.996Z

Reserved: 2026-01-20T21:50:41.239Z

Link: CVE-2025-15541

cve-icon Vulnrichment

Updated: 2026-01-29T20:37:22.145Z

cve-icon NVD

Status : Received

Published: 2026-01-29T19:16:11.143

Modified: 2026-01-29T19:16:11.143

Link: CVE-2025-15541

cve-icon Redhat

No data.