CVE-2024-46548

TP-Link Tapo P125M and Kasa KP125M v1.0.3 was discovered to improperly validate certificates, allowing attackers to eavesdrop on communications and access sensitive information via a man-in-the-middle attack.
Configurations

No configuration.

History

04 Oct 2024, 13:51

Type Values Removed Values Added
Summary
  • (es) Se descubrió que TP-Link Tapo P125M y Kasa KP125M v1.0.3 validaban incorrectamente los certificados, lo que permitía a los atacantes espiar las comunicaciones y acceder a información confidencial a través de un ataque de intermediario.

30 Sep 2024, 21:35

Type Values Removed Values Added
CWE CWE-200
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.3

30 Sep 2024, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-09-30 17:15

Updated : 2024-10-04 13:51


NVD link : CVE-2024-46548

Mitre link : CVE-2024-46548

CVE.ORG link : CVE-2024-46548


JSON object : View

Products Affected

No product.

CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor