Description
Multiple
TP-Link Kasa smart home devices contain insufficient cryptographic protections
in the local device communication protocol. An adjacent network attacker may
intercept, replay or forge locally exchanged control messages, potentially
resulting in unauthorized device control.









Successful
exploitation could allow an attacker to manipulate the operational state of an
affected device, resulting in unauthorized state changes, disruption of normal
device functionality or a denial-of-service condition.
Published: 2026-08-26
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the local device communication protocol of TP‑Link Kasa smart home devices, where the cryptographic protections are insufficient. An adjacent network attacker can intercept, replay, or forge locally exchanged control messages. By manipulating these messages, the attacker can alter the operational state of the device, causing unauthorized state changes, normal functionality disruption, or a denial‑of‑service condition.

Affected Systems

The affected products include a range of TP‑Link Kasa devices such as EP10, EP25 V2, EP40A, EP40M, ES20M, HS103P3 / HS103P4 v5, HS200 V5.26, HS220 V3.26, HS220‑LA/BL 4.6 and 6.6, HS300 V2, KL125, KP115, KP125MP2 / KP125MP4, KP200 V3, KP303 V2, KS205, KS220M, KS225, and KS240.

Risk and Exploitability

The CVSS score of 8.7 indicates high severity, while the EPSS score is not available and the vulnerability is not listed in CISA KEV. The exploit is likely achievable by an attacker who has local network access; no additional conditions are specified in the description. Because the weakness involves improper cryptographic strength (CWE‑325), it can be leveraged to bypass authentication and gain control over the device’s state.

Generated by OpenCVE AI on August 26, 2026 at 20:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update all affected TP‑Link devices to the latest firmware provided on the TP‑Link support site.
  • If firmware updates are not immediately available, restrict local device communication by configuring the home router’s firewall to block ports used by the Kasa protocol or by placing the devices on a separate network segment.
  • Strengthen network security by enforcing WPA2/WPA3 encryption and using a strong, unique passphrase, limiting LAN connectivity to trusted devices only.

Generated by OpenCVE AI on August 26, 2026 at 20:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 26 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description Multiple TP-Link Kasa smart home devices contain insufficient cryptographic protections in the local device communication protocol. An adjacent network attacker may intercept, replay or forge locally exchanged control messages, potentially resulting in unauthorized device control. Successful exploitation could allow an attacker to manipulate the operational state of an affected device, resulting in unauthorized state changes, disruption of normal device functionality or a denial-of-service condition.
Title Insufficient Cryptographic Protections in Local Device Communication Protocol on Multiple TP-Link Kasa Smart Home Devices
Weaknesses CWE-325
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: TPLink

Published:

Updated: 2026-08-26T18:50:19.860Z

Reserved: 2026-08-19T17:32:21.874Z

Link: CVE-2026-76784

cve-icon Vulnrichment

Updated: 2026-08-26T18:50:12.831Z

cve-icon NVD

Status : Received

Published: 2026-08-26T18:17:01.903

Modified: 2026-08-26T20:18:01.487

Link: CVE-2026-76784

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T20:15:03Z

Weaknesses
  • CWE-325

    Missing Cryptographic Step