Answer in brief
CVE-2026-76784 records a Unknown severity vulnerability in Insufficient Cryptographic Protections in Local Device Communication Protocol on Multiple TP-Link Kasa Smart Home Devices. The current sources do not mark it as known exploited. The current feed maps TP-Link Systems Inc./EP10 (generic), TP-Link Systems Inc./EP25 V2 (generic), TP-Link Systems Inc./EP40A (generic), TP-Link Systems Inc./EP40M (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps TP-Link Systems Inc./EP10 (generic), TP-Link Systems Inc./EP25 V2 (generic), TP-Link Systems Inc./EP40A (generic), TP-Link Systems Inc./EP40M (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| TP-Link Systems Inc./EP10generic | >=0 <1.1.1 Build 250908 Rel.112508 | 1.1.1 Build 250908 Rel.112508 |
| TP-Link Systems Inc./EP25 V2generic | >=0 <1.0.3 Build 240529 Rel.145252 | 1.0.3 Build 240529 Rel.145252 |
| TP-Link Systems Inc./EP40Ageneric | >=0 <1.1.1 Build 250908 Rel.112526 | 1.1.1 Build 250908 Rel.112526 |
| TP-Link Systems Inc./EP40Mgeneric | >=0 <1.1.0 Build 240415 Rel.171219 | 1.1.0 Build 240415 Rel.171219 |
| TP-Link Systems Inc./ES20Mgeneric | >=0 <1.1.6 Build 250522 Rel.210254 | 1.1.6 Build 250522 Rel.210254 |
| TP-Link Systems Inc./HS103P3 / HS103P4 v5generic | >=0 <1.1.3 Build 250908 Rel.112508 | 1.1.3 Build 250908 Rel.112508 |
| TP-Link Systems Inc./HS200 V5.26generic | >=0 <1.0.3 Build 240723 Rel.192622 | 1.0.3 Build 240723 Rel.192622 |
| TP-Link Systems Inc./HS220-LA(US) 4.6 / HS220-BL(US) 4.6generic | >=0 <1.1.1 Build 240802 Rel.094142 | 1.1.1 Build 240802 Rel.094142 |
| TP-Link Systems Inc./HS220-LA(US) 6.6 / HS220-BL(US) 6.6generic | >=0 <1.0.3 Build 240723 Rel.192630 | 1.0.3 Build 240723 Rel.192630 |
| TP-Link Systems Inc./HS220 V3.26generic | >=0 <1.1.1 Build 240802 Rel.094131 | 1.1.1 Build 240802 Rel.094131 |
| TP-Link Systems Inc./HS300 V2generic | >=0 <1.1.2 Build 241220 Rel.171333 | 1.1.2 Build 241220 Rel.171333 |
| TP-Link Systems Inc./KL125generic | >=0 <1.1.1 Build 260710 Rel.082646 | 1.1.1 Build 260710 Rel.082646 |
| TP-Link Systems Inc./KP115generic | >=0 <1.1.1 Build 250908 Rel.112945 | 1.1.1 Build 250908 Rel.112945 |
| TP-Link Systems Inc./KP125MP2 / KP125MP4generic | >=0 <1.2.5 Build 241213 Rel.172504 | 1.2.5 Build 241213 Rel.172504 |
| TP-Link Systems Inc./KP200 V3generic | >=0 <1.1.0 Build 250225 Rel.171724 | 1.1.0 Build 250225 Rel.171724 |
| TP-Link Systems Inc./KP303 V2generic | >=0 <1.1.2 Build 241220 Rel.173321 | 1.1.2 Build 241220 Rel.173321 |
| TP-Link Systems Inc./KS205generic | >=0 <1.1.1 Build 240724 Rel.105920 | 1.1.1 Build 240724 Rel.105920 |
| TP-Link Systems Inc./KS220Mgeneric | >=0 <1.1.6 Build 250522 Rel.210254 | 1.1.6 Build 250522 Rel.210254 |
| TP-Link Systems Inc./KS225generic | >=0 <1.1.1 Build 240626 Rel.175125 | 1.1.1 Build 240626 Rel.175125 |
| TP-Link Systems Inc./KS240generic | >=0 <1.0.6 Build 240122 Rel.160100 | 1.0.6 Build 240122 Rel.160100 |
Published upstream
Aug 26, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 26, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 26, 2026
Multiple TP-Link Kasa smart home devices contain insufficient cryptographic protections in the local device communication protocol. An adjacent network attacker may intercept, replay or forge locally exchanged control messages, potentially resulting in unauthorized device control. Successful exploitation could allow an attacker to manipulate the operational state of an affected device, resulting in unauthorized state changes, disruption of normal device functionality or a denial-of-service condition.
Quoted source text, attributed separately from HOL analysis.