CVE-2024-35495

Medium severity, CVSS 4.3. EPSS: 0.2% chance of exploitation in the next 30 days.

An Information Disclosure vulnerability in the Telemetry component in TP-Link Kasa KP125M V1.0.0 and Tapo P125M 1.0.0 Build 220930 Rel.143947 allows attackers to observe device state via observing network traffic.

Published 2024-09-30. Last modified 2026-06-17.