TP-Link Kasa Smart Home Devices Vulnerability Allows Attackers to Disrupt Device Functionality
Brief
TP-Link has disclosed a high-severity vulnerability affecting multiple Kasa smart home devices that could allow attackers on the same local network to intercept, replay, or forge device-control commands.
Tracked as CVE-2026-76784, the flaw can lead to unauthorized changes to device state, disruption of normal functionality, or denial-of-service conditions.
The security advisory, last updated on August 26, 2026, attributes the issue to insufficient cryptographic protections in the local device communication protocol used by affected Kasa products. The vulnerability carries a CVSS v4. 0 score of 8. 7, rated High.
An attacker must be adjacent to the target device, meaning they need access to the same local network or wireless environment. No authentication, privileges, or user interaction are required for exploitation.
