Sensitive Data Exposure due to Hardcoded Cryptographic Keys in Multiple TP-Link Aginet Devices

Note: This data is for reference and cybersecurity research purposes only.CyStack advises users not to use this information for unlawful purposes.

What is CVE-2025-30239?

CVE-2025-30239 is a vulnerability classified as Use of Hard-coded Cryptographic Key, affecting HB810(US2) V1.0/1.6/2.0/2.6 (affected versions: < 0.9.0 3.2.2 v6095.0 Build 260717 Rel.67188n), HB810(EU1) V2.0 (affected versions: < 0.10.0 3.2.2 v6095.0 Build 260306 Rel.47567n), HB710(US2) V1.6/1.0 (affected versions: < 0.3.0 3.0.0 v60be.0 Build 251128 Rel.43956n), and 62 more products. This vulnerability is rated High, with a CVSS score of 8.5. Current sources do not report this vulnerability as exploited.

Analyzing data...

Overview

Original source data

In affected TP-Link Aginet devices, use of hardcoded cryptographic keys embedded in the firmware to protect sensitive configuration data may allow an attacker who has access to device storage to recover the keys and decrypt stored data.

Successful exploitation may allow access to decrypted sensitive configuration data, including credentials and service-related information.

Affected products and scope

The analysis could not be completed. The original vulnerability data remains available below.

Technical details

The analysis could not be completed. The original vulnerability data remains available below.

Exploitability

The analysis could not be completed. The original vulnerability data remains available below.

Technical impact

The analysis could not be completed. The original vulnerability data remains available below.

Business impact

The analysis could not be completed. The original vulnerability data remains available below.

Remediation

The analysis could not be completed. The original vulnerability data remains available below.

Detection

The analysis could not be completed. The original vulnerability data remains available below.
Sources (6)
Learn more

Run an in-depth assessment with complete web risk management

CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.

Explore CyStack VulnScan