CVE-2024-46549: Tplink Kasa KP125M
High severity, CVSS 7.6. EPSS: 0.4% chance of exploitation in the next 30 days.
An issue in the TP-Link MQTT Broker and API gateway of TP-Link Kasa KP125M v1.0.3 allows attackers to establish connections by impersonating devices owned by other users.
Affected products
- Tplink Kasa KP125M: version 1.0.3 only
Published 2024-09-30. Last modified 2026-06-17.