CVE-2024-35495

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Sep 30, 2024
Updated: Oct 30, 2024
CWE ID 319

Summary

CVE-2024-35495 is a newly disclosed Information Disclosure vulnerability affecting the Telemetry component of TP-Link Kasa KP125M V1.0.0 and Tapo P125M 1.0.0 Build 220930 Rel.143947. This issue enables attackers to gain insights into device states by monitoring network traffic, potentially exposing sensitive information. The vulnerability does not require user interaction or authentication, increasing the severity of the threat. Users are encouraged to update their devices to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share