CVE-2025-15541 describes an improper link resolution vulnerability in the VX800v v1.0 SFTP service. This flaw allows authenticated adjacent attackers to leverage crafted symbolic links to gain unauthorized access to system files. The vulnerability carries a CVSS score of 6.9 (Medium), indicating a high confidentiality impact and limited integrity risk, with an attack requiring high privileges and adjacent network access. Currently, there is no known public exploit code, active exploitation, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 800.0.11CPE matchmatch criteria | cpe:2.3:o:tp-link:vx800v_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.