CVE-2026-76784
Awaiting Analysis Awaiting Analysis - Queue

TP-Link Kasa Smart Home Devices Cryptographic Protocol Weakness

Vulnerability report for CVE-2026-76784, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-26

Last updated on: 2026-08-28

Assigner: TPLink

Description

Multiple TP-Link Kasa smart home devices contain insufficient cryptographic protections in the local device communication protocol. An adjacent network attacker may intercept, replay or forge locally exchanged control messages, potentially resulting in unauthorized device control. Successful exploitation could allow an attacker to manipulate the operational state of an affected device, resulting in unauthorized state changes, disruption of normal device functionality or a denial-of-service condition.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-26
Last Modified
2026-08-28
Generated
2026-09-16
AI Q&A
2026-08-26
EPSS Evaluated
2026-09-14
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
tp-link kasa *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-325 The product does not implement a required step in a cryptographic algorithm, resulting in weaker encryption than advertised by the algorithm.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-76784 is a vulnerability in TP-Link Kasa smart home devices caused by weak cryptographic protections in their local communication protocol. An attacker within close proximity to the network can intercept, replay, or forge control messages to gain unauthorized access to devices.

Detection Guidance

Detection requires monitoring network traffic for unencrypted or weakly encrypted local device communications. Use packet capture tools like Wireshark to inspect traffic between TP-Link Kasa devices and your network. Look for plaintext control messages or repeated patterns indicating replay attacks. Check device firmware versions against TP-Link's advisory for known vulnerable releases.

Impact Analysis

This vulnerability may allow an attacker to manipulate device states, disrupt normal functionality, or cause a denial-of-service. Unauthorized control could lead to privacy risks, physical damage, or loss of device availability.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by exposing sensitive data or enabling unauthorized control of devices. Insufficient cryptographic protections may allow attackers to intercept or manipulate device communications, leading to unauthorized access or data breaches. This could violate privacy requirements under GDPR and compromise protected health information under HIPAA.

Mitigation Strategies

Immediately update all TP-Link Kasa devices to the latest firmware versions provided by TP-Link. Isolate affected devices on a separate network segment if possible. Disable remote access features if not required. Monitor device behavior for unauthorized changes and restrict physical access to network infrastructure.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-76784. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart