CVE-2025-15543 Details
Description
Improper link resolution in USB HTTP access path in VX800v v1.0 allows a crafted USB device to expose root filesystem contents, giving an attacker with physical access read‑only access to system files.
A vulnerability in the TP-Link VX800v router, specifically in version 1.0, has been identified that allows a crafted USB device to exploit improper link resolution in the USB HTTP access path. This exploitation gives an attacker with physical access read-only access to the root filesystem, enabling them to view system files. The vulnerability arises from the router's failure to properly validate links in the USB access path, allowing unauthorized access to sensitive filesystem contents.
Users are advised to update to the latest firmware version. The VX800v firmware can be downloaded from the TP-Link support page for this product.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jan 29, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.tp-link.com/de/support/download/vx800v/#Firmware | TPLink | Product |
| https://www.tp-link.com/us/support/faq/4930/ | TPLink | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-59 | Improper Link Resolution Before File Access ('Link Following') | TPLink |
Affected Products
| Product | Versions |
|---|---|
| tp-link vx800v firmware | < 800.0.11 |
CPE
Remediation
| |
| tp-link vx800v | 1.0 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | TPLink |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 9, 2026 | Initial Analysis | [email protected] |
| Jan 29, 2026 | New CVE Received | TPLink |