- Description
- Improper link resolution in the VX800v v1.0 SFTP service allows authenticated adjacent attackers to use crafted symbolic links to access system files, resulting in high confidentiality impact and limited integrity risk.
- Source
- f23511db-6c3e-4e32-a477-6aa17d310630
- NVD status
- Analyzed
- Products
- vx800v_firmware
CVSS 4.0
- Type
- Secondary
- Base score
- 6.9
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity
- MEDIUM
CVSS 3.1
- Type
- Primary
- Base score
- 6.3
- Impact score
- 4.2
- Exploitability score
- 2.1
- Vector string
- CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
- Severity
- MEDIUM
- f23511db-6c3e-4e32-a477-6aa17d310630
- CWE-59
- Hype score
- Not currently trending
CVE-2025-15541 Symbolic Link Vulnerability in VX800v v1.0 SFTP Service Enables Unauthorized File Access https://t.co/BD336ZOMAz
@VulmonFeeds
30 Jan 2026
71 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-15541 Improper link resolution in the VX800v v1.0 SFTP service allows authenticated adjacent attackers to use crafted symbolic links to access system files, resulting in hi… https://t.co/qeK1Vg0wIC
@CVEnew
29 Jan 2026
108 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:tp-link:vx800v_firmware:*:*:*:*:*:*:*:*",
"matchCriteriaId": "D323DA3B-C62D-433E-980E-78A9C575D676",
"versionEndExcluding": "800.0.11",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
},
{
"cpeMatch": [
{
"criteria": "cpe:2.3:h:tp-link:vx800v:1.0:*:*:*:*:*:*:*",
"matchCriteriaId": "10362289-8BD9-4B51-A347-6E4DA2BC6507",
"vulnerable": false
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "AND"
}
]