TLS Communication Vulnerability in TP-Link Products
CVE-2025-9293
7.7HIGH
Key Information:
- Vendor
Tp-link Systems Inc.
- Vendor
- CVE Published:
- 13 February 2026
What is CVE-2025-9293?
A vulnerability in the certificate validation process of TP-Link networking devices may result in applications trusting untrusted or improperly validated server identities during TLS communication. Attackers positioned within the network could intercept or alter traffic, leading to potential compromises in confidentiality, integrity, and availability of sensitive application data. It is crucial for users to assess their devices and apply necessary updates to mitigate these risks.
Affected Version(s)
Aginet App Android 0 < 2.13.6
Deco App Android 0 < 3.9.163
Festa App Android 0 < 1.7.1
References
CVSS V4
Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Francesco La Spina, Stanislav Dashevskyi from Forescout Technologies
