CVE-2024-46549

CVSS 3.1 Score 7.6 of 10 (high)

Details

Published Sep 30, 2024
Updated: Oct 4, 2024
CWE ID 269

Summary

CVE-2024-46549 is a newly disclosed vulnerability affecting the TP-Link Kasa KP125M v1.0.3 MQTT Broker and API gateway. This issue enables unauthorized users to establish connections by impersonating devices owned by other users. Attackers can potentially gain access to these devices and control them without the legitimate owner's knowledge. This vulnerability poses a significant risk to privacy and security, especially in smart home environments where multiple devices are interconnected. Users are advised to update their devices to the latest firmware as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share