CVE-2024-46548: Tplink Kasa KP125M

Medium severity, CVSS 6.3. EPSS: 0.2% chance of exploitation in the next 30 days.

TP-Link Tapo P125M and Kasa KP125M v1.0.3 was discovered to improperly validate certificates, allowing attackers to eavesdrop on communications and access sensitive information via a man-in-the-middle attack.

Affected products

  • Tplink Kasa KP125M: version 1.0.3 only
  • Tplink Tapo p125m: version 1.0.3 only

Published 2024-09-30. Last modified 2026-06-17.