Cyber Security News

TP-Link Kasa Smart Home Flaw Lets Attackers Forge Control Messages and Take Control of Devices

TP-Link has revealed a critical vulnerability in Kasa smart home devices that could allow an attacker on the same local network to intercept, replay, or forge control messages, potentially manipulating affected products.

This issue, tracked as CVE-2026-76784, arises from inadequate cryptographic protections in the protocol used for local communications among Kasa devices.

TP-Link has assigned the flaw a CVSS v4 score of 8.7, categorizing it as High. The company updated its advisory on August 26, 2026, urging customers to install the available firmware updates.

This vulnerability is classified as adjacent-network exploitable, meaning the attacker must have access to the victim device through its local network environment, such as a compromised Wi-Fi network or another point of entry on the same LAN. The CVSS vector indicates low attack complexity, no required privileges, and no interaction needed from users.

Due to the affected protocol’s inability to adequately safeguard commands exchanged locally, an attacker could observe valid messages and resend them or create forged commands.

TP-Link has noted that successful exploitation could result in unauthorized changes to the operational state, disruption of normal functionality, or even a denial-of-service condition.

In practical terms, this could allow an attacker to remotely turn compatible plugs, switches, bulbs, or light strips on or off, depending on the device’s capabilities and the forged command.

The list of affected products includes Kasa Plug/Switch and Bulb/Light Strip models. The models receiving fixes include HS103P3/HS103P4, EP10, EP25 V2, HS300 V2, KP303 V2, EP40A, KP125MP2/KP125MP4, KP115, KS225, EP40M, KS205, KS240, ES20M, KS220M, KP200 V3, HS200 V5.26, several HS220 variants, and the KL125 bulb.

Firmware build numbers vary by model. For example, TP-Link lists version 1.1.3 Build 250908 Rel.112508 for HS103P3 and HS103P4, version 1.1.1 Build 250908 Rel.112508 for EP10, and version 1.1.1 Build 260710 Rel.082646 for the KL125. Users should verify their specific model and hardware version before applying an update.

To update affected Kasa devices, users can visit TP-Link’s Download Center or follow the product’s supported management workflow.

Until patches are applied, organizations and individual users should limit untrusted access to IoT network segments, isolate smart home devices from sensitive systems, secure Wi-Fi access, and monitor for unexpected changes in device states.

While network segmentation does not replace the need for a firmware fix, it can help reduce exposure to potential attackers on the same network.

This advisory highlights a persistent concern in IoT security: local control channels require integrity and replay protections, rather than relying solely on assumptions about network proximity. For Kasa device owners, applying the appropriate model-specific firmware remains the primary method of remediation.

Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC

Divya

Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Recent Posts

CISA Warns of Actively Exploited Citrix NetScaler ADC and Gateway Vulnerability

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-8452, a vulnerability affecting Citrix…

5 minutes ago

Hackers Are Targeting AI Servers to Steal API Keys and Hijack Computing Power

AI infrastructure is rapidly becoming a high-value enterprise attack surface. Attackers targeting LiteLLM AI gateways,…

9 minutes ago

Ransomware Hacker Uses AI to Plan Attacks and Compromises More Than 20 Organizations

A Russian-speaking affiliate of the Aurora ransomware operation compromised more than 20 organizations across nine…

1 hour ago

CISA Warns of Actively Exploited Microsoft SQL Server RCE Vulnerability

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2019-1068, a remote code execution…

1 hour ago

FBI Seizes China State-Sponsored Hacker Platforms Used to Target U.S. Critical Infrastructure

The U.S. Justice Department and the FBI have seized domains associated with two hacking platforms…

2 hours ago

AccuKnox Launches AgentZ to Help Enterprises Build, Run, and Govern AI Agents at Scale

Menlo Park, California, USA, August 27th, 2026, CyberNewswire AccuKnox today announced the launch of AgentZ,…

2 hours ago