TP-Link VX800v Improper Link Resolution in SFTP Service Allowing Unauthorized Access to System Files

Vulnerability

A vulnerability in the TP-Link VX800v router, specifically in version 1.0, has been identified within the SFTP service. This vulnerability arises from improper link resolution, which allows authenticated adjacent attackers to exploit crafted symbolic links to access system files. The issue poses a significant risk to confidentiality and a limited risk to integrity.

Impact

Exploitation of this vulnerability could lead to unauthorized access to sensitive system files, with a high impact on confidentiality and a limited impact on integrity.

Remediation

Users are advised to update to the latest firmware version. The latest firmware for the VX800v can be downloaded from the TP-Link support page for this product.

Added: Jan 29, 2026, 7:25 PM
Updated: Jan 29, 2026, 7:25 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
3.5
remediation
0.0
relevance
2.5
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.