CVE-2025-9293Disclosure(tp-link / aginet)

LOWCVSS 8.1 · HIGH

Signal is active with 5 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability in the certificate validation logic may allow applications to accept untrusted or improperly validated server identities during TLS communication. An attacker in a privileged network position may be able to intercept or modify traffic if they can position themselves within the communication channel. Successful exploitation may compromise confidentiality, integrity, and availability of application data.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-295

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • aginet
  • deco
  • festa
  • kasa

Threat summary

  • 5 mentions across 1 observed day

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 5 classified signals
  • 5 total mentions across 1 day

Affected systems

Vendors
Products
aginetdecofestakasakidshieldomadaomada_guardtapotethertp-partner

Deep dive

Activity timeline5 mentions / 1d
01345Mentions · 2026-02-13: 5Technical Details · 2026-02-13: 402-13
Signal classification1 categories
Disclosure
5100.0%
Referenced assets3 URLs
Full discourse5 posts
  • CVE@CVEnew
    Disclosure

    CVE-2025-9293 A vulnerability in the certificate validation logic may allow applications to accept untrusted or improperly validated server identities during TLS communication. An at… https://www.cve.org/CVERecord?id=CVE-2025-9293

    Post summary

    CVE-2025-9293 describes a flaw in TLS certificate validation that could cause applications to accept untrusted server identities.

    00020519
    56.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2025-9293 TLS Certificate Validation Vulnerability Enables Potential Man-in-the-Middle Attacks https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-9293

    Post summary

    A TLS certificate validation flaw (CVE‑2025‑9293) could enable man‑in‑the‑middle attacks; no PoC, exploit, patch, or active exploitation details are provided.

    1001049
    4.0K followersView on X
  • transilienceai@transilienceai
    Disclosure

    @rangeva @VulmonFeeds 🚨 **CVE-2025-9293** is a high-severity vulnerability (CVSS v4.0 score: 7.7/High) in multiple TP-Link mobile applications, including the TP-Link Tapo App, due to insufficient TLS certificate validation. #CyberSecurity #Vulnerability

    Post summary

    The tweet announces CVE-2025-9293, a high‑severity TLS validation flaw in TP‑Link mobile apps, providing basic technical details but no evidence of exploitation or mitigation.

    1000064
    315 followersView on X
  • transilienceai@transilienceai
    Disclosure

    @VulmonFeeds 🚨 **CVE-2025-9293** is a high-severity vulnerability (CVSS v4.0 score: 7.7/High) in the certificate validation logic of multiple TP-Link mobile applications. It enables potential man-in-the-middle (MITM) attacks during TLS communication. #CyberSecurity #VulnerabilityAlert 🔒

    Post summary

    The post announces the discovery of CVE‑2025‑9293, a high‑severity certificate validation flaw in TP‑Link mobile applications that could enable MITM attacks during TLS communication.

    1000048
    315 followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2025-9293 📊 Severity: 7.7 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2025-9293 #CVE-2025-9293 #CVE #High #CyberSecurity #InfoSec https://t.co/jx9dfiMUmu

    Post summary

    The tweet announces the new CVE-2025-9293 with a severity rating of 7.7 but provides no further technical or mitigation details.

    0000043
    57 followersView on X
CPE platform detail14 entries

14 of 14 entries

PartVendorProductVersionTarget SWTarget HW
Apptp-linkaginet---
Apptp-linkdeco---
Apptp-linkfesta---
Apptp-linkkasa---
Apptp-linkkidshield---
Apptp-linkomada---
Apptp-linkomada_guard---
Apptp-linktapo---
Apptp-linktether---
Apptp-linktp-partner---
Apptp-linktpcamera---
Apptp-linkvigi---
Apptp-linkwi-fi_navi---
Apptp-linkwifi_toolkit---

Explore more