CVE-2025-9292Disclosure(tp-link / aginet)

LOWCVSS 7.5 · HIGH

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A permissive web security configuration may allow cross-origin restrictions enforced by modern browsers to be bypassed under specific circumstances. Exploitation requires the presence of an existing client-side injection vulnerability and user access to the affected web interface. Successful exploitation could allow unauthorized disclosure of sensitive information. Fixed in updated Omada Cloud Controller service versions deployed automatically by TP‑Link. No user action is required.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-942

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • aginet
  • deco
  • festa
  • kasa

Threat summary

  • 4 mentions across 1 observed day

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • 4 total mentions across 1 day

Affected systems

Vendors
Products
aginetdecofestakasakidshieldomadaomada_guardtapotethertp-partner

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-02-13: 4Technical Details · 2026-02-13: 402-13
Signal classification1 categories
Disclosure
4100.0%
Referenced assets2 URLs
Full discourse4 posts
  • CVE@CVEnew
    Disclosure

    CVE-2025-9292 A permissive web security configuration may allow cross-origin restrictions enforced by modern browsers to be bypassed under specific circumstances. Exploitation requi… https://www.cve.org/CVERecord?id=CVE-2025-9292

    Post summary

    The text announces CVE‑2025‑9292, describing a permissive web security configuration that could allow cross‑origin restrictions to be bypassed.

    00020545
    56.5K followersView on X
  • transilienceai@transilienceai
    Disclosure

    @rangeva @VulmonFeeds Related but distinct: CVE-2025-9292 affects Omada Cloud Controllers with a cross-origin bypass (low severity, 2.0). #Vulnerability #CVE

    Post summary

    CVE-2025-9292 is a low‑severity cross‑origin bypass vulnerability in Omada Cloud Controllers, with no evidence of PoC, exploitation, or patch mentioned.

    1000027
    315 followersView on X
  • transilienceai@transilienceai
    Disclosure

    @VulmonFeeds This CVE appears alongside **CVE-2025-9292** (CVSS 2.0/Low) in the same TP-Link advisory, affecting Omada Cloud Controllers with a permissive web security policy allowing cross-origin bypass. #CVE #Vulnerability

    Post summary

    A new CVE (CVE‑2025‑9292) is disclosed in a TP‑Link advisory for Omada Cloud Controllers, noting a low‑severity cross‑origin bypass due to a permissive web security policy.

    1000052
    315 followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2025-9292 📊 Severity: 2.0 🚨 Risk Level: Low 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2025-9292 #CVE-2025-9292 #CVE #Low #CyberSecurity #InfoSec https://t.co/Pigc5APSbB

    Post summary

    The tweet announces CVE-2025-9292, noting its low severity and linking to the NVD entry for further details.

    0000031
    57 followersView on X
CPE platform detail14 entries

14 of 14 entries

PartVendorProductVersionTarget SWTarget HW
Apptp-linkaginet---
Apptp-linkdeco---
Apptp-linkfesta---
Apptp-linkkasa---
Apptp-linkkidshield---
Apptp-linkomada---
Apptp-linkomada_guard---
Apptp-linktapo---
Apptp-linktether---
Apptp-linktp-partner---
Apptp-linktpcamera---
Apptp-linkvigi---
Apptp-linkwi-fi_navi---
Apptp-linkwifi_toolkit---

Explore more