PT-2024-32030 · Tp Link · Tp-Link Tapo P125M+1

Agatah2333

+1

·

Published

2024-06-20

·

Updated

2024-10-04

·

CVE-2024-46548

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions TP-Link Tapo P125M and Kasa KP125M version 1.0.3
Description The issue allows attackers to eavesdrop on communications and access sensitive information via a man-in-the-middle attack due to improper validation of certificates.
Recommendations For TP-Link Tapo P125M and Kasa KP125M version 1.0.3, update the firmware to a version that properly validates certificates to prevent man-in-the-middle attacks.

Exploit

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

BDU:2025-02467
CVE-2024-46548

Affected Products

Kasa Kp125M
Tp-Link Tapo P125M