{"id":"CVE-2026-76784","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-76784","summary":"Multiple\nTP-Link Kasa smart home devices contain insufficient cryptographic protections\nin the local device communication protocol. An adjacent network attacker may\nintercept, replay…","details":"Multiple\nTP-Link Kasa smart home devices contain insufficient cryptographic protections\nin the local device communication protocol. An adjacent network attacker may\nintercept, replay or forge locally exchanged control messages, potentially\nresulting in unauthorized device control. \n\n\n\n\n\n\n\n\n\nSuccessful\nexploitation could allow an attacker to manipulate the operational state of an\naffected device, resulting in unauthorized state changes, disruption of normal\ndevice functionality or a denial-of-service condition.","published":"2026-08-26T18:17:01.903","modified":"2026-08-26T20:18:01.487","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://www.tp-link.com/en/support/download/"},{"type":"WEB","url":"https://www.tp-link.com/in/support/download/"},{"type":"WEB","url":"https://www.tp-link.com/us/support/download/"},{"type":"WEB","url":"https://www.tp-link.com/us/support/faq/5267/"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-08-26T20:18:01.487"}}