CVE-2025-15543 describes an improper link resolution vulnerability (CWE-59) in the VX800v v1.0, specifically within its USB HTTP access path. This flaw allows a physically present attacker, using a specially crafted USB device, to gain read-only access to the device's root filesystem contents. The vulnerability has a CVSSv4 score of 5.1 (MEDIUM), indicating a low attack complexity and no user interaction required, but it necessitates physical access to the device (Attack Vector: Physical). The primary impact is high confidentiality, as system files can be exposed, though integrity and availability are not directly affected. Currently, there is no known active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE. Its EPSS score is very low, suggesting a minimal likelihood of exploitation in the wild.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 800.0.11CPE matchmatch criteria | cpe:2.3:o:tp-link:vx800v_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.