Click to skip the navigation bar

Security Advisory: Insufficient Cryptographic Protections in Local Device Communication Protocol on Multiple Kasa Smart Home Devices (CVE-2026-76784)

Security Advisory
Last updated: August 26, 2026

Vulnerability Description and Impact:

CVE-2026-76784: Insufficient Cryptographic Protections in Local Device Communication Protocol

Multiple TP-Link Kasa smart home devices contain insufficient cryptographic protections in the local device communication protocol. An adjacent network attacker may intercept, replay or forge locally exchanged control messages, potentially resulting in unauthorized device control.

Successful exploitation could allow an attacker to manipulate the operational state of an affected device, resulting in unauthorized state changes, disruption of normal device functionality or a denial-of-service condition.

CVSS v4.0 Score: 8.7 / High

CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N

Affected Products/Versions and Fixes:

Model

Fixed Version

Plug/Switch

HS103P3/HS103P4

1.1.3 Build 250908 Rel.112508

EP10

1.1.1 Build 250908 Rel.112508

EP25 V2

1.0.3 Build 240529 Rel.145252

HS300 V2

1.1.2 Build 241220 Rel.171333

KP303 V2

1.1.2 Build 241220 Rel.173321

EP40A

1.1.1 Build 250908 Rel.112526

KP125MP2/KP125MP4

1.2.5 Build 241213 Rel.172504

KP115

1.1.1 Build 250908 Rel.112945

KS225

1.1.1 Build 240626 Rel.175125

EP40M

1.1.0 Build 240415 Rel.171219

KS205

1.1.1 Build 240724 Rel.105920

KS240

1.0.6 Build 240122 Rel.160100

ES20M

1.1.6 Build 250522 Rel.210254

KS220M

1.1.6 Build 250522 Rel.210254

KP200 V3

1.1.0 Build 250225 Rel.171724

HS200 V5.26

1.0.3 Build 240723 Rel.192622

HS220-LA(US) V6.6 / HS220-BL(US) V6.6

1.0.3 Build 240723 Rel.192630

HS220 V3.26

1.1.1 Build 240802 Rel.094131

HS220-LA(US) V4.6 / HS220-BL(US) V4.6

1.1.1 Build 240802 Rel.094142

Bulb/Light Strip

KL125

1.1.1 Build 260710 Rel.082646

Recommendations:

We strongly recommend that users with affected devices take the following actions:

  1. Follow the instructions to update to the latest firmware version:

US: Download Center | TP-Link

EN: Download Center | TP-Link

Disclaimer:

This advisory is provided for informational purposes only and is subject to change without notice. The information is provided “as is” without warranties of any kind. TP-Link recommends that customers promptly apply available firmware updates or implement documented workarounds as provided in this advisory. Devices/systems that are not updated or mitigated as described may remain vulnerable, and TP-Link disclaims any responsibility or liability for any damages or losses arising from a failure to implement such updates.

Related FAQs

Looking For More

Is this faq useful?

Your feedback helps improve this site.

Community

TP-Link Community

Still need help? Search for answers, ask questions, and get help from TP-Link experts and other users around the world.

Visit the Community >