CVE-2026-76784 HIGH

CVE-2026-76784: Insufficient Cryptographic Protections in Local Device Communication Protocol on Multiple TP-Link Kasa Smart Home Devices

Vendor Tp-Link Systems Inc.
Product HS103P3 / HS103P4 v5
Weakness CWE-325
Published August 26, 2026
Last update August 26, 2026

CVSS base score

8.7/10
Attack vector Adjacent
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

What the vulnerability does

01Description

Multiple TP-Link Kasa smart home devices contain insufficient cryptographic protections in the local device communication protocol. An adjacent network attacker may intercept, replay or forge locally exchanged control messages, potentially resulting in unauthorized device control. Successful exploitation could allow an attacker to manipulate the operational state of an affected device, resulting in unauthorized state changes, disruption of normal device functionality or a denial-of-service condition.

Key dates

02Disclosure timeline

August 26, 2026 CVE published
August 26, 2026 Record updated