← back
CVE-2025-15541

Access to System Files via SFTP on TP-Link VX800v

CVSS 6.9 MEDIUMEPSS 0.3%CWE-59
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 6.9EPSS 0.3%KEV nãoPoC Nuclei Metasploit Patch referenciado
Lifecycle
29 Jan 2026Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Improper link resolution in the VX800v v1.0 SFTP service allows authenticated adjacent attackers to use crafted symbolic links to access system files, resulting in high confidentiality impact and limited integrity risk.
CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →