CVE-2026-76784
Multiple TP-Link Kasa smart home devices contain insufficient cryptographic protections in the local device communication protocol. An adjacent network attacker may intercept, replay or forge locally exchanged control messages, potentially resulting in unauthorized device control. Successful exploitation could allow an attacker to manipulate the operational state of an affected device, resulting in unauthorized state changes, disruption of normal device functionality or a denial-of-service condition.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.7
- CVSS vector
- CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 0.15%
- CWE
- CWE-325
- Published
- 2026-08-26
- Last modified
- 2026-08-26
Affected products
- TP-Link Systems Inc. HS103P3 / HS103P4 v5
- TP-Link Systems Inc. EP10
- TP-Link Systems Inc. EP25 V2
- TP-Link Systems Inc. HS300 V2
- TP-Link Systems Inc. KP303 V2
- TP-Link Systems Inc. EP40A
- TP-Link Systems Inc. KP125MP2 / KP125MP4
- TP-Link Systems Inc. KP115
Weakness type
Related vulnerabilities
- CVE-2026-25250 — EAZ EazyFix 12.9 allows a Security Feature Bypass related to a "Missing Cryptographic Step"...
- CVE-2026-59776 — Missing Cryptographic Step (CWE-325) vulnerability exists in certain FeliCa IC chips shipped in or...
- CVE-2026-58638 — Windows Boot Loader Security Feature Bypass Vulnerability
- CVE-2026-55144 — Windows Cryptography API: Next Generation (CNG) Tampering Vulnerability
- CVE-2026-6458 — AES-256-GCM Authentication Tag Does Not Cover First Ciphertext Blocks When AAD Is Empty
- CVE-2026-49440 — Deno: Miller-Rabin Primality Test Allows Zero Rounds
- CVE-2026-9266 — A Missing Required Cryptographic Step vulnerability has been identified in Moxa's embedded Linux...
- CVE-2026-45446 — Incorrect Tag Processing for Empty Messages in AES-GCM-SIV and AES-SIV modes