CVE-2026-76784

Summary

Multiple TP-Link Kasa smart home devices contain insufficient cryptographic protections in the local device communication protocol. An adjacent network attacker may intercept, replay or forge locally exchanged control messages, potentially resulting in unauthorized device control.

Successful exploitation could allow an attacker to manipulate the operational state of an affected device, resulting in unauthorized state changes, disruption of normal device functionality or a denial-of-service condition.

Affected Software

VendorProductVersion RangeStatus
TP-Link Systems Inc.HS103P3 / HS103P4 v50 < 1.1.3 Build 250908 Rel.112508affected
TP-Link Systems Inc.EP100 < 1.1.1 Build 250908 Rel.112508affected
TP-Link Systems Inc.EP25 V20 < 1.0.3 Build 240529 Rel.145252affected
TP-Link Systems Inc.HS300 V20 < 1.1.2 Build 241220 Rel.171333affected
TP-Link Systems Inc.KP303 V20 < 1.1.2 Build 241220 Rel.173321affected
TP-Link Systems Inc.EP40A0 < 1.1.1 Build 250908 Rel.112526affected
TP-Link Systems Inc.KP125MP2 / KP125MP40 < 1.2.5 Build 241213 Rel.172504affected
TP-Link Systems Inc.KP1150 < 1.1.1 Build 250908 Rel.112945affected
TP-Link Systems Inc.KS2250 < 1.1.1 Build 240626 Rel.175125affected
TP-Link Systems Inc.EP40M0 < 1.1.0 Build 240415 Rel.171219affected
TP-Link Systems Inc.KS2050 < 1.1.1 Build 240724 Rel.105920affected
TP-Link Systems Inc.KS2400 < 1.0.6 Build 240122 Rel.160100affected
TP-Link Systems Inc.ES20M0 < 1.1.6 Build 250522 Rel.210254affected
TP-Link Systems Inc.KS220M0 < 1.1.6 Build 250522 Rel.210254affected
TP-Link Systems Inc.KP200 V30 < 1.1.0 Build 250225 Rel.171724affected
TP-Link Systems Inc.HS200 V5.260 < 1.0.3 Build 240723 Rel.192622affected
TP-Link Systems Inc.HS220-LA(US) 6.6 / HS220-BL(US) 6.60 < 1.0.3 Build 240723 Rel.192630affected
TP-Link Systems Inc.HS220 V3.260 < 1.1.1 Build 240802 Rel.094131affected
TP-Link Systems Inc.HS220-LA(US) 4.6 / HS220-BL(US) 4.60 < 1.1.1 Build 240802 Rel.094142affected
TP-Link Systems Inc.KL1250 < 1.1.1 Build 260710 Rel.082646affected

Weaknesses

  • CWE-325: CWE-325: Missing Cryptographic Step

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References