CVE-2026-76784

Unauthorized device control via forgeable local messages

Published Aug 26, 2026 · Updated Aug 26, 2026

Missing cryptographic protection in TP-Link Kasa smart home devices allows attackers on an adjacent network to forge local control messages. The local device communication protocol omits a necessary cryptographic step, so captured control traffic can be intercepted, replayed, or forged. Network adjacency is sufficient; successful messages can change device state, disrupt normal operation, or interrupt service.

CVSS severity8.7
High
EPSS probability0.15%
Next 30 days · Sep 16, 2026
Known exploitationUnconfirmed
Based on sourced intelligence
Hinoki checkNot available
Coverage for this vulnerability

See if you're affected

Explore vulnerability checks for your environment with Hinoki.

Book a demo

Summary

What happened

Missing cryptographic protection in TP-Link Kasa smart home devices allows attackers on an adjacent network to forge local control messages. The local device communication protocol omits a necessary cryptographic step, so captured control traffic can be intercepted, replayed, or forged. Network adjacency is sufficient; successful messages can change device state, disrupt normal operation, or interrupt service.

The record

CVE
CVE-2026-76784
Published
Aug 26, 2026
Updated
Aug 26, 2026
Vendor
TP-Link Systems Inc.
Product
Kasa Smart Wi‑Fi Light Switch (HS200)
Classifications
CWE-325, CAPEC-594, T1565.002
Attack vector
adjacent
Privileges
unauthenticated

Timeline

How it unfolded

  1. Aug 26, 2026CVE publishedPublication date reported by the CVE source.
  2. Aug 26, 2026Record updatedLatest update available in the CVE record.

Exploitability

Present is not the same as exploitable

Compare your product and version with the public record. A matching version still requires validation against your environment.

Is a vulnerable build present?

Compare these published version ranges with your installed build and any vendor patches.

  1. Affected versionversion=0 <1.0.3 Build 240723 Rel.192622

What conditions does exploitation require?

Attack vectoradjacent
Required privilegesunauthenticated

What is affected?

TP-Link Systems Inc. · Kasa Smart Wi‑Fi Light Switch (HS200)version=0 <1.0.3 Build 240723 Rel.192622
TP-Link Systems Inc. · Kasa Smart Wi‑Fi Plug (HS103P3/HS103P4)version=0 <1.1.3 Build 250908 Rel.112508
TP-Link Systems Inc. · Kasa Smart Wi‑Fi Light Switch, Matter (KS205)version=0 <1.1.1 Build 240724 Rel.105920
TP-Link Systems Inc. · Kasa Smart Wi‑Fi Outdoor Plug (EP40M)version=0 <1.1.0 Build 240415 Rel.171219
TP-Link Systems Inc. · Kasa Smart Wi‑Fi Plug Slim with Energy Monitoring (KP125MP2/KP125MP4)version=0 <1.2.5 Build 241213 Rel.172504
TP-Link Systems Inc. · Kasa Smart Wi‑Fi Dimmer Light Switch, Matter (KS225)version=0 <1.1.1 Build 240626 Rel.175125
TP-Link Systems Inc. · Kasa Smart Wi‑Fi Plug Mini (EP10)version=0 <1.1.1 Build 250908 Rel.112508
TP-Link Systems Inc. · Kasa Smart Wi‑Fi Light Switch, Dimmer (HS220)version=0 <1.1.1 Build 240802 Rel.094131
TP-Link Systems Inc. · Kasa Smart Wi‑Fi Outdoor Plug (EP40A)version=0 <1.1.1 Build 250908 Rel.112526
TP-Link Systems Inc. · Kasa Smart Wi‑Fi Dimmer Switch, Motion-Activated (KS220M)version=0 <1.1.6 Build 250522 Rel.210254
TP-Link Systems Inc. · Kasa Smart Ceiling Fan Control & Dimmer Switch (KS240)version=0 <1.0.6 Build 240122 Rel.160100
TP-Link Systems Inc. · Kasa Smart Light Bulb, Multicolor (KL125)version=0 <1.1.1 Build 260710 Rel.082646
TP-Link Systems Inc. · Kasa Smart Wi‑Fi Power Outlet, 2-Sockets (KP200)version=0 <1.1.0 Build 250225 Rel.171724
TP-Link Systems Inc. · Smart Wi‑Fi Dimmer Switch, Motion Activated (ES20M)version=0 <1.1.6 Build 250522 Rel.210254
TP-Link Systems Inc. · Kasa Smart Wi‑Fi Plug Slim with Energy Monitoring (KP115)version=0 <1.1.1 Build 250908 Rel.112945
TP-Link Systems Inc. · Kasa Smart Wi‑Fi Light Switch, Dimmer (HS220-LA/HS220-BL)version=0 <1.0.3 Build 240723 Rel.192630; version=0 <1.1.1 Build 240802 Rel.094142
TP-Link Systems Inc. · Kasa Smart Wi-Fi Power Strip (KP303)version=0 <1.1.2 Build 241220 Rel.173321
TP-Link Systems Inc. · Kasa Smart Wi‑Fi Power Strip, 6-Outlets (HS300)version=0 <1.1.2 Build 241220 Rel.171333
TP-Link Systems Inc. · Kasa Smart Wi‑Fi Plug Slim with Energy Monitoring (EP25)version=0 <1.0.3 Build 240529 Rel.145252

Published CVSS scores

8.7TP-Link Systems Inc.CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

CVSS describes severity. EPSS estimates exploitation probability.

Attacks

What attackers are doing with it

Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.

Daily unique IPsNo honeypot observations are available for this CVE in the selected window.

No observations available

Sep 10, 2026Sep 16, 2026
Latest reporting daySep 16, 2026
Latest daily unique IPsUnavailable
Prior 30-day averageUnavailable
SourceShadowserver honeypots (KEV)
Vectoradjacent
Privilegesunauthenticated
Known exploitationUnconfirmed
Public exploitUnconfirmed

Weakness, pattern, technique

CWE-325Missing Cryptographic Step
CAPEC-594Traffic Injection
T1565.002Transmitted Data Manipulation

Public exploit references

No public exploit references are available in this record.

Labels summarize the accepted research assessment. They do not indicate a test against your environment.

Technologies

Your stack

See the directory against your own environment.

Your stack

Check the software in your environment

Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.

Book a demo