CVE-2025-9292: TP-Link Aginet

High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.

A permissive web security configuration may allow cross-origin restrictions enforced by modern browsers to be bypassed under specific circumstances. Exploitation requires the presence of an existing client-side injection vulnerability and user access to the affected web interface. Successful exploitation could allow unauthorized disclosure of sensitive information. Fixed in updated Omada Cloud Controller service versions deployed automatically by TP‑Link. No user action is required.

Affected products

  • TP-Link Aginet: before 2.13.6 (fixed in 2.13.6)
  • TP-Link Deco: before 3.9.163 (fixed in 3.9.163)
  • TP-Link Festa: before 1.7.1 (fixed in 1.7.1)
  • TP-Link Kasa: before 3.4.350 (fixed in 3.4.350)
  • TP-Link Kidshield: before 1.1.21 (fixed in 1.1.21)
  • TP-Link Omada: before 4.25.25 (fixed in 4.25.25)
  • TP-Link Omada Guard: before 1.1.28 (fixed in 1.1.28)
  • TP-Link Tapo: before 3.14.111 (fixed in 3.14.111)
  • TP-Link Tether: before 4.12.27 (fixed in 4.12.27)
  • TP-Link TP-Partner: before 2.0.1 (fixed in 2.0.1)
  • TP-Link Tpcamera: before 3.2.17 (fixed in 3.2.17)
  • TP-Link Vigi: before 2.7.70 (fixed in 2.7.70)
  • TP-Link Wi-Fi Navi: before 1.5.5 (fixed in 1.5.5)
  • TP-Link Wifi Toolkit: before 1.4.28 (fixed in 1.4.28)

Published 2026-02-13. Last modified 2026-06-17.