CVE-2025-9293

High8.1Published on February 13, 2026

A vulnerability in the certificate validation logic may allow applications to accept untrusted or improperly validated server identities during TLS communication. An attacker in a privileged network position may be able to intercept or modify traffic if they can position themselves within the communication channel. Successful exploitation may compromise confidentiality, integrity, and availability of application data.

CVSS score8.1 / 10CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness type (CWE)CWE-295
Vendorstp-link

Affected products

VendorsProductVersions
tp-linkaginet< 2.13.6
tp-linkdeco< 3.9.163
tp-linkfesta< 1.7.1
tp-linkkasa< 3.4.350
tp-linkkidshield< 1.1.21
tp-linkomada< 4.25.25
tp-linkomada guard< 1.1.28
tp-linktapo< 3.14.111
tp-linktether< 4.12.27
tp-linktp-partner< 2.0.1
tp-linktpcamera< 3.2.17
tp-linkvigi< 2.7.70
tp-linkwi-fi navi< 1.5.5
tp-linkwifi toolkit< 1.4.28

Related articles

This product uses the NVD API but is not endorsed or certified by the NVD.

CVE database