Insufficient Certificate Validation in Multiple Mobile Applications Allows Man in the Middle Interception
Published Feb 13, 2026
7.7
HIGHCVSS 4.0
EPSS 0.23%
Description
A vulnerability in the certificate validation logic may allow applications to accept untrusted or improperly validated server identities during TLS communication. An attacker in a privileged network position may be able to intercept or modify traffic if they can position themselves within the communication channel. Successful exploitation may compromise confidentiality, integrity, and availability of application data.
Affected products
-
- Version 0StatusaffectedConstraints<4.25.25
- Version
-
- Version 0StatusaffectedConstraints<2.13.6
- Version
-
- Version 0StatusaffectedConstraints<3.9.163
- Version
-
- Version 0StatusaffectedConstraints<1.7.1
- Version
-
- Version 0StatusaffectedConstraints<3.4.350
- Version
-
- Version 0StatusaffectedConstraints<1.1.21
- Version
-
- Version 0StatusaffectedConstraints<1.1.28
- Version
-
- Version 0StatusaffectedConstraints<2.0.1
- Version
-
- Version 0StatusaffectedConstraints<3.14.111
- Version
-
- Version 0StatusaffectedConstraints<4.12.27
- Version
-
- Version 0StatusaffectedConstraints<2.7.70
- Version
-
- Version 0StatusaffectedConstraints<1.5.5
- Version
-
- Version 0StatusaffectedConstraints<1.4.28
- Version
-
- Version 0StatusaffectedConstraints<3.2.17
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| TP Link Systems Inc. | Omada App | unaffected |
| ||||||
| TP-Link Systems Inc. | Aginet App | unaffected |
| ||||||
| TP-Link Systems Inc. | Deco App | unaffected |
| ||||||
| TP-Link Systems Inc. | Festa App | unaffected |
| ||||||
| TP-Link Systems Inc. | Kasa App | unaffected |
| ||||||
| TP-Link Systems Inc. | KidShield | unaffected |
| ||||||
| TP-Link Systems Inc. | Omada Guard | unaffected |
| ||||||
| TP-Link Systems Inc. | TP-Partner App | unaffected |
| ||||||
| TP-Link Systems Inc. | Tapo App | unaffected |
| ||||||
| TP-Link Systems Inc. | Tether App | unaffected |
| ||||||
| TP-Link Systems Inc. | VIGI App | unaffected |
| ||||||
| TP-Link Systems Inc. | Wi-Fi Navi | unaffected |
| ||||||
| TP-Link Systems Inc. | WiFi Toolkit | unaffected |
| ||||||
| TP-Link Systems Inc. | tpCamera App | unaffected |
|
- < 2.13.6
- < 3.9.163
- < 1.7.1
- < 3.4.350
- < 1.1.21
- < 4.25.25
- < 1.1.28
- < 3.14.111
- < 4.12.27
- < 2.0.1
- < 3.2.17
- < 2.7.70
- < 1.5.5
- < 1.4.28
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:L/SI:N/SA:N
1 other source (NVD) ▾
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed Feb 13, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 2, 2026.
Score over time
Feb–Oct 2026- EPSS v4
- EPSS v5
Percentile over time
- EPSS v4
- EPSS v5
Table of values (3 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 2, 2026 | 0.23% (0.00233) | 12.89th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.22% (0.00224) | 12.87th | v5 (v2026.06.15) |
| Feb 13, 2026 | 0.02% (0.00023) | 5.71th | v4 (v2025.03.14) |
References (2)
- https://www.omadanetworks.com/us/support/faq/4969/ vendor-advisoryVendor Advisory
- https://www.tp-link.com/us/support/faq/4969/ vendor-advisoryVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://www.omadanetworks.com/us/support/faq/4969/ | vendor-advisoryVendor Advisory | |
| https://www.tp-link.com/us/support/faq/4969/ | vendor-advisoryVendor Advisory |
Change history (0)
No recorded changes yet.