← Back to CVE List
Vulnerability Intelligence Report
Insufficient Certificate Validation in Multiple Mobile Applications Allows Man in the Middle Interception

CVE-2025-9293

A vulnerability in the certificate validation logic may allow applications to accept untrusted or improperly validated server identities during TLS communication. An attacker in a privileged network position may be able to intercept or modify traffic if they can position themselves within the communication channel. Successful exploitation may compromise confidentiality, integrity, and availability of application data.

No Active Exploit Signals
CVSS Base Score
7.7
HIGH
EPSS Probability:0.22%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-295 ↗CWE-295 Improper Certificate Validation

Affected Products & Versions

Vendor Product Affected Versions
TP-Link Systems Inc. Tapo App 0 < 3.14.111 (affected)
TP-Link Systems Inc. Kasa App 0 < 3.4.350 (affected)
TP Link Systems Inc. Omada App 0 < 4.25.25 (affected)
TP-Link Systems Inc. Omada Guard 0 < 1.1.28 (affected)
TP-Link Systems Inc. Tether App 0 < 4.12.27 (affected)
TP-Link Systems Inc. Deco App 0 < 3.9.163 (affected)
TP-Link Systems Inc. Aginet App 0 < 2.13.6 (affected)
TP-Link Systems Inc. tpCamera App 0 < 3.2.17 (affected)
TP-Link Systems Inc. WiFi Toolkit 0 < 1.4.28 (affected)
TP-Link Systems Inc. Festa App 0 < 1.7.1 (affected)
TP-Link Systems Inc. Wi-Fi Navi 0 < 1.5.5 (affected)
TP-Link Systems Inc. KidShield 0 < 1.1.21 (affected)
TP-Link Systems Inc. TP-Partner App 0 < 2.0.1 (affected)
TP-Link Systems Inc. VIGI App 0 < 2.7.70 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
0.224%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityTP-Link Systems Inc. · Vendor · USA
Reserved2025-08-20T22:29:42
Published2026-02-13T00:22:27
Last Updated2026-02-13T22:10:15

LINK COPIED TO CLIPBOARD