A critical flaw in TP-Link’s Kasa smart home range enables attackers on the same local network to intercept and manipulate device commands without user interaction, prompting urgent firmware updates to mitigate risks.
TP-Link has issued a security advisory for a flaw in its Kasa smart home range that could let an attacker on the same local network intercept, replay or forge device control messages. The weakness, tracked as CVE-2026-76784, stems from inadequate cryptographic protection in the protocol used for local communication between devices. TP-Link says the issue carries a CVSS v4 score of 8.7 and has urged customers to install available firmware updates, with the advisory updated on 26 August 2026.
The vulnerability is significant because it does not require the victim to click a link or approve a prompt. According to TP-Link’s advisory, an attacker only needs access to the adjacent network, such as a compromised Wi-Fi environment or another foothold on the same LAN. That gives the attacker an opportunity to observe legitimate commands and then resend them or construct forged messages, potentially changing how affected devices behave.
In practical terms, the flaw could allow unauthorised switching of compatible plugs, bulbs, light strips and other Kasa hardware on or off, depending on the product’s capabilities and the command being manipulated. TP-Link says exploitation could also cause service disruption or denial of service. Security summaries from Omada Networks and CVE tracking services describe the same attack path and severity rating, reinforcing that the weakness sits in the trust model for local control traffic rather than in cloud access.
TP-Link’s patched list covers a wide set of models, including several Kasa Plug, Switch, Bulb and Light Strip devices. The company’s support pages provide model-specific firmware, and users are being told to verify both the exact model and hardware revision before updating. Among the fixed builds listed are HS103P3 and HS103P4 at version 1.1.3 Build 250908 Rel.112508, EP10 at version 1.1.1 Build 250908 Rel.112508, and KL125 at version 1.1.1 Build 260710 Rel.082646.
Until updates are installed, TP-Link recommends basic network hygiene: keep untrusted devices off sensitive segments, isolate IoT gear from critical systems, secure Wi-Fi access and watch for unexpected changes in device state. The broader lesson is familiar to IoT defenders: local control channels need integrity and replay protection, not just network proximity assumptions. For Kasa owners, the firmware fix remains the primary remediation.
Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.





