Security Advisory: Insufficient Cryptographic Protections in Local Device Communication Protocol on Multiple Kasa Smart Home Devices (CVE-2026-76784)
Vulnerability Description and Impact:
CVE-2026-76784: Insufficient Cryptographic Protections in Local Device Communication Protocol
Multiple TP-Link Kasa smart home devices contain insufficient cryptographic protections in the local device communication protocol. An adjacent network attacker may intercept, replay or forge locally exchanged control messages, potentially resulting in unauthorized device control.
Successful exploitation could allow an attacker to manipulate the operational state of an affected device, resulting in unauthorized state changes, disruption of normal device functionality or a denial-of-service condition.
CVSS v4.0 Score: 8.7 / High
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N
Affected Products/Versions and Fixes:
|
Model |
Fixed Version |
|
Plug/Switch |
|
|
HS103P3/HS103P4 |
1.1.3 Build 250908 Rel.112508 |
|
EP10 |
1.1.1 Build 250908 Rel.112508 |
|
EP25 V2 |
1.0.3 Build 240529 Rel.145252 |
|
HS300 V2 |
1.1.2 Build 241220 Rel.171333 |
|
KP303 V2 |
1.1.2 Build 241220 Rel.173321 |
|
EP40A |
1.1.1 Build 250908 Rel.112526 |
|
KP125MP2/KP125MP4 |
1.2.5 Build 241213 Rel.172504 |
|
KP115 |
1.1.1 Build 250908 Rel.112945 |
|
KS225 |
1.1.1 Build 240626 Rel.175125 |
|
EP40M |
1.1.0 Build 240415 Rel.171219 |
|
KS205 |
1.1.1 Build 240724 Rel.105920 |
|
KS240 |
1.0.6 Build 240122 Rel.160100 |
|
ES20M |
1.1.6 Build 250522 Rel.210254 |
|
KS220M |
1.1.6 Build 250522 Rel.210254 |
|
KP200 V3 |
1.1.0 Build 250225 Rel.171724 |
|
HS200 V5.26 |
1.0.3 Build 240723 Rel.192622 |
|
HS220-LA(US) V6.6 / HS220-BL(US) V6.6 |
1.0.3 Build 240723 Rel.192630 |
|
HS220 V3.26 |
1.1.1 Build 240802 Rel.094131 |
|
HS220-LA(US) V4.6 / HS220-BL(US) V4.6 |
1.1.1 Build 240802 Rel.094142 |
|
Bulb/Light Strip |
|
|
KL125 |
1.1.1 Build 260710 Rel.082646 |
Recommendations:
We strongly recommend that users with affected devices take the following actions:
- Follow the instructions to update to the latest firmware version:
Disclaimer:
This advisory is provided for informational purposes only and is subject to change without notice. The information is provided “as is” without warranties of any kind. TP-Link recommends that customers promptly apply available firmware updates or implement documented workarounds as provided in this advisory. Devices/systems that are not updated or mitigated as described may remain vulnerable, and TP-Link disclaims any responsibility or liability for any damages or losses arising from a failure to implement such updates.
Looking For More
Is this faq useful?
Your feedback helps improve this site.
TP-Link Community
Still need help? Search for answers, ask questions, and get help from TP-Link experts and other users around the world.