Impact
The vulnerability resides in the local device communication protocol of TP‑Link Kasa smart home devices, where the cryptographic protections are insufficient. An adjacent network attacker can intercept, replay, or forge locally exchanged control messages. By manipulating these messages, the attacker can alter the operational state of the device, causing unauthorized state changes, normal functionality disruption, or a denial‑of‑service condition.
Affected Systems
The affected products include a range of TP‑Link Kasa devices such as EP10, EP25 V2, EP40A, EP40M, ES20M, HS103P3 / HS103P4 v5, HS200 V5.26, HS220 V3.26, HS220‑LA/BL 4.6 and 6.6, HS300 V2, KL125, KP115, KP125MP2 / KP125MP4, KP200 V3, KP303 V2, KS205, KS220M, KS225, and KS240.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity, while the EPSS score is not available and the vulnerability is not listed in CISA KEV. The exploit is likely achievable by an attacker who has local network access; no additional conditions are specified in the description. Because the weakness involves improper cryptographic strength (CWE‑325), it can be leveraged to bypass authentication and gain control over the device’s state.
OpenCVE Enrichment