6.9
/ 10
MEDIUM
CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N
Description
Improper link resolution in the VX800v v1.0 SFTP service allows authenticated adjacent attackers to use crafted symbolic links to access system files, resulting in high confidentiality impact and limited integrity risk.
Basic Information
ID
CVE-2025-15541
Source
TPLink
Published
Jan 29, 2026 at 18:05
Affected Product
Vendor
TP-Link Systems Inc.
Product
VX800v v1.0
Affected Versions
TP-Link Systems Inc. VX800v v1.0 0