CVE-2026-76784CWE-325

CVE-2026-76784

published August 26, 2026

CVSS
8.7
EPSS
0%
Percentile
4.2
In the wild
Unconfirmed
What it is

Multiple

TP-Link Kasa smart home devices contain insufficient cryptographic protections

in the local device communication protocol. An adjacent network attacker may

intercept, replay or forge locally exchanged control messages, potentially

resulting in unauthorized device control.

Successful

exploitation could allow an attacker to manipulate the operational state of an

affected device, resulting in unauthorized state changes, disruption of normal

device functionality or a denial-of-service condition.

The record
Technical detail
CVSS
8.7 · NONE
CVSS v4.0
8.7 · CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS
0.00146 · 4.2th percentile
Weakness
CWE-325 · Missing Cryptographic Step
Published
2026-08-26T22:17Z
References (4)
EPSS history
Timeline
  • 28 AUG 06:53Z
    EPSS moved — → 0%
    epss
  • 26 AUG 17:47Z
    Insufficient Cryptographic Protections in Local Device Communication Protocol on Multiple TP-Link Kasa Smart Home Devices
    cvelistv5