Chapoly1305/tp-link-cve

Chapoly1305/tp-link-cve

Releases0
Write-ups for TP-Link product issues.

CVE History

CVEPublishedCVSS v3CVSS v2
4.3 MEDIUM

An Information Disclosure vulnerability in the Telemetry component in TP-Link Kasa KP125M V1.0.0 and Tapo P125M 1.0.0 Build 220930 Rel.143947 allows attackers to observe device state via observing network traffic.

6.3 MEDIUM

TP-Link Tapo P125M and Kasa KP125M v1.0.3 was discovered to improperly validate certificates, allowing attackers to eavesdrop on communications and access sensitive information via a man-in-the-middle attack.

7.6 HIGH

An issue in the TP-Link MQTT Broker and API gateway of TP-Link Kasa KP125M v1.0.3 allows attackers to establish connections by impersonating devices owned by other users.