Insufficient Cryptographic Protections in TP-Link Kasa Smart Home Devices
CVE-2026-76784

8.7HIGH

What is CVE-2026-76784?

TP-Link Kasa smart home devices exhibit vulnerabilities due to insufficient cryptographic safeguards in their local communication protocol. This deficiency enables adjacent network attackers to intercept, replay, or forge control messages exchanged between devices. Consequently, this could lead to unauthorized manipulation of device functionality, disruptions in service, or even denial-of-service attacks. Users should be aware of these vulnerabilities and ensure they apply available security patches to mitigate risks.

Affected Version(s)

EP10 0 < 1.1.1 Build 250908 Rel.112508

EP25 V2 0 < 1.0.3 Build 240529 Rel.145252

EP40A 0 < 1.1.1 Build 250908 Rel.112526

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Priyanka Rushikesh Chaudhary (Research Scholar, CSIS Department, BITS Pilani, Hyderabad Campus, India), Rajib Ranjan Maiti (Associate Professor, CSIS Department, BITS Pilani, Hyderabad Campus, India)
.