Cyber Security News

TP-Link Kasa Smart Home Devices Vulnerability Allows Attackers to Disrupt Device Functionality

TP-Link has disclosed a high-severity vulnerability affecting multiple Kasa smart home devices that could allow attackers on the same local network to intercept, replay, or forge device-control commands.

Tracked as CVE-2026-76784, the flaw can lead to unauthorized changes to device state, disruption of normal functionality, or denial-of-service conditions.

The security advisory, last updated on August 26, 2026, attributes the issue to insufficient cryptographic protections in the local device communication protocol used by affected Kasa products. The vulnerability carries a CVSS v4.0 score of 8.7, rated High.

An attacker must be adjacent to the target device, meaning they need access to the same local network or wireless environment. No authentication, privileges, or user interaction are required for exploitation.

This could increase risk in shared Wi-Fi environments, compromised home networks, guest networks, or enterprise deployments where smart devices share network access with less trusted systems.

According to TP-Link, the weakness may allow an attacker to capture control messages exchanged locally between the Kasa app, the device, or other local components.

The attacker could then replay previously valid commands or forge new messages due to inadequate cryptographic safeguards protecting command integrity and authenticity.

Successful exploitation could let an attacker turn smart plugs, switches, and lighting products on or off without authorization. In practical scenarios, this could interrupt connected appliances, turn off lighting, alter schedules, or repeatedly issue commands to make a device unavailable.

The impact is particularly relevant for Kasa devices used in home offices, small businesses, retail environments, or automated facilities.

The affected product list includes Kasa smart plugs and switches such as HS103P3, HS103P4, EP10, EP25 V2, HS300 V2, KP303 V2, EP40A, KP125MP2, KP125MP4, KP115, KS225, KS205, KS240, ES20M, KS220M, KP200 V3, HS200 V5.26, and several HS220 variants. The KL125 smart bulb is also affected.

TP-Link has released fixed firmware versions for the listed devices. For example, HS103P3 and HS103P4 users should update to version 1.1.3 Build 250908 Rel.112508, while KL125 users should install version 1.1.1 Build 260710 Rel.082646.

Users should verify their exact hardware version before applying firmware, as Kasa firmware releases vary by model and regional variant.

Users are advised to update affected devices through the TP-Link Download Center or the Kasa Smart application. Until updates are installed, organizations and consumers should isolate IoT devices on a separate network or VLAN, restrict access from guest Wi-Fi networks, and monitor for unusual device behavior.

CVE-2026-76784 highlights the security consequences of weak protection for local IoT communications. Even when devices are not directly exposed to the internet, attackers who gain local network access may still manipulate physical systems connected to vulnerable smart home products.

Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC

Abinaya

Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

2 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

3 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

4 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

4 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

4 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

6 hours ago