CVE-2026-76784: Insufficient Cryptographic Protections in Local Device Communication Protocol on Multiple TP-Link Kasa Smart Home Devices
Multiple TP-Link Kasa smart home devices contain insufficient cryptographic protections in the local device communication protocol. An adjacent network attacker may intercept, replay or forge locally exchanged control messages, potentially resulting in unauthorized device control.
Successful exploitation could allow an attacker to manipulate the operational state of an affected device, resulting in unauthorized state changes, disruption of normal device functionality or a denial-of-service condition.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker must be adjacent to the network used for local device communications. The described impact is limited to locally exchanged control messages rather than requiring remote access over the internet.
What could an attacker do after exploiting it?
An attacker may intercept, replay, or forge local control messages. This can lead to unauthorized device state changes, disruption of normal operation, or denial of service.
Which TP-Link Kasa devices or software versions are affected?
The provided information identifies multiple TP-Link Kasa smart home devices but does not list specific models or affected software versions. Consult TP-Link's support download resources for device-specific update information.