Improper link resolution in the VX800v v1.0 SFTP service allows authenticated adjacent attackers to use crafted symbolic links to access system files, resulting in high confidentiality impact and limited integrity risk.
References
| Link | Resource |
|---|---|
| https://www.tp-link.com/de/support/download/vx800v/#Firmware | Product |
| https://www.tp-link.com/us/support/faq/4930/ | Vendor Advisory |
Configurations
Configuration 1 (hide)
| AND |
|
History
No history.
Information
Published : 2026-01-29 19:16
Updated : 2026-03-09 17:51
NVD link : CVE-2025-15541
Mitre link : CVE-2025-15541
CVE.ORG link : CVE-2025-15541
JSON object : View
Products Affected
tp-link
- vx800v
- vx800v_firmware
CWE
CWE-59
Improper Link Resolution Before File Access ('Link Following')
