TP-Link has warned about a high-severity security vulnerability affecting several Kasa smart plugs, switches, and other smart home products.
Tracked as CVE-2026-76784, the flaw could allow an attacker on the same local network to send unauthorized commands to vulnerable devices. The issue has a CVSS v4.0 score of 8.7.
The vulnerability is caused by weaknesses in the security used to protect communication between Kasa devices and their local control components.
Attackers Could Manipulate Device Commands
An attacker does not need an account or special permissions to exploit the issue. However, they must have access to the same local network or wireless environment as the targeted device.
This could make shared Wi-Fi networks, compromised home networks, and poorly separated business networks potential attack environments.
Attackers could potentially capture legitimate device commands and reuse them or create their own commands.
Depending on the device, this could allow someone to:
- Turn smart plugs, switches, or lights on or off
- Interrupt connected appliances
- Change device behavior or schedules
- Repeatedly send commands and disrupt normal operation
The affected products include several Kasa smart plugs, switches, and the KL125 smart bulb, along with other models.
Firmware Updates Are Available
TP-Link has released updated firmware for affected products. Because firmware versions depend on the specific model, hardware revision, and region, users should check their exact device before installing an update.
Users can look for the latest firmware through the TP-Link Download Center or Kasa Smart app.
Until devices are updated, users and organizations can reduce their exposure by:
- Placing IoT devices on a separate network or VLAN
- Keeping smart devices away from sensitive systems
- Limiting access from guest networks
- Watching for unexpected device activity
The vulnerability is a reminder that smart home devices do not need to be directly exposed to the internet to become a security concern. An attacker who gains access to the local network may still be able to manipulate vulnerable IoT devices.