Новости компьютерной безопасности:

  Latest News

TP-Link Kasa Smart Home Devices Vulnerability Allows Attackers to Disrupt Device Functionality

С сайта: Vulnerability(cybersecuritynews.com)

TP-Link Kasa Smart Home Devices Vulnerability Allows Attackers to Disrupt Device Functionality

Author: Abinaya

TP-Link has disclosed a high-severity vulnerability affecting multiple Kasa smart home devices that could allow attackers on the same local network to intercept, replay, or forge device-control commands.

Tracked as CVE-2026-76784, the flaw can lead to unauthorized changes to device state, disruption of normal functionality, or denial-of-service conditions.

The security advisory, last updated on August 26, 2026, attributes the issue to insufficient cryptographic protections in the local device communication protocol used by affected Kasa products. The vulnerability carries a CVSS v4.0 score of 8.7, rated High.

An attacker must be adjacent to the target device, meaning they need access to the same local network or wireless environment. No authentication, privileges, or user interaction are required for exploitation.

This could increase risk in shared Wi-Fi environments, compromised home networks, guest networks, or enterprise deployments where smart devices share network access with less trusted systems.

TP-Link Kasa Smart Home Devices Vulnerability
According to TP-Link, the weakness may allow an attacker to capture control messages exchanged locally between the Kasa app, the device, or other local components.

The attacker could then replay previously valid commands or forge new messages due to inadequate cryptographic safeguards protecting command integrity and authenticity.

Successful exploitation could let an attacker turn smart plugs, switches, and lighting products on or off without authorization. In practical scenarios, this could interrupt connected appliances, turn off lighting, alter schedules, or repeatedly issue commands to make a device unavailable.

The impact is particularly relevant for Kasa devices used in home offices, small businesses, retail environments, or automated facilities.

The affected product list includes Kasa smart plugs and switches such as HS103P3, HS103P4, EP10, EP25 V2, HS300 V2, KP303 V2, EP40A, KP125MP2, KP125MP4, KP115, KS225, KS205, KS240, ES20M, KS220M, KP200 V3, HS200 V5.26, and several HS220 variants. The KL125 smart bulb is also affected.

TP-Link has released fixed firmware versions for the listed devices. For example, HS103P3 and HS103P4 users should update to version 1.1.3 Build 250908 Rel.112508, while KL125 users should install version 1.1.1 Build 260710 Rel.082646.

Users should verify their exact hardware version before applying firmware, as Kasa firmware releases vary by model and regional variant.

Users are advised to update affected devices through the TP-Link Download Center or the Kasa Smart application. Until updates are installed, organizations and consumers should isolate IoT devices on a separate network or VLAN, restrict access from guest Wi-Fi networks, and monitor for unusual device behavior.

CVE-2026-76784 highlights the security consequences of weak protection for local IoT communications. Even when devices are not directly exposed to the internet, attackers who gain local network access may still manipulate physical systems connected to vulnerable smart home products.

Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC



#Cyber_Security_News #Vulnerability #cyber_security #cyber_security_news

Оригинальная версия на сайте: TP-Link Kasa Smart Home Devices Vulnerability Allows Attackers to Disrupt Device Functionality
Вернуться к списку новостей К свежим новостям Здесь был google AdSense.
Вместо рекламы товаров началась политическая агитация.
Отключено до получения извинений.

Вернуться к списку новостей Здесь был google AdSense.
Вместо рекламы товаров началась политическая агитация.
Отключено до получения извинений.


Новости проекта CSN:

✉ CSN.net4me.net

Обновление сайта csn.net4me.net

Обновление сайта csn.net4me.net 💻
cyber security news
  • Физически мы переехали на новый сервер. Благодарим наших подписчиков и постоянных читателей за терпение и понимание.
  • Сайт csn.net4me.net полностью адаптирован для работы по шифрованному SSL соединению.
  • Изменен механизм обработки и отображения опасных и критических уязвимостей.

Благодарим что вы с нами.


#CSN_обновление_сайта
https://csn.net4me.net/cyber_security_8301.html

Дополнительный материал

О проекте CSN

Проект CSN.net4me.net родился 16 Марта 2018 года.
Проект находится в самом начале своего развития. Конечно оформление, наполнение будет меняться. Одно останется неизменным - самые свежие новости компьютерной и сетевой безопасности.

О проекте net4me

Проект net4me.net развивался как сборник готовых решений и документации по темам компьютерной безопасности, сетевых решений и СПО (в часности linux). Темпы развития IT отрасли оказались столь быстрыми, что некоторые знания, технологии и информация о них устаревали мгновенно. Тем не менее, некоторый материал net4me.net до сих пор востребован.

Об источниках

Новости берутся CSN из открытых и доступных каждому источников. Авторы проекта стараются подбирать авторитетные и проверенные источники. Но, тем не менее, не несут ответственности за содержимое новостей. В каждой новости указывается источник этой новости, её автор и ссылка на оригинал новости.

Информация

Если вы желаете чтобы новости вашего ресурса были размещены на сайте CSN, то свяжитесь с авторами проекта csn@net4me.net и предложите ссылку на rss или xml ленту новостей вашего ресурса. Любая предложенная информация будет рассмотрена редакцией.