Куда я попал?
SECURITM это SGRC система, ? автоматизирующая процессы в службах информационной безопасности. SECURITM помогает построить и управлять ИСПДн, КИИ, ГИС, СМИБ/СУИБ, банковскими системами защиты.
А еще SECURITM это место для обмена опытом и наработками для служб безопасности.

CVE-2026-76784

PUBLISHED 26.08.2026

CNA: TPLink

Insufficient Cryptographic Protections in Local Device Communication Protocol on Multiple TP-Link Kasa Smart Home Devices

Обновлено: 26.08.2026
Multiple TP-Link Kasa smart home devices contain insufficient cryptographic protections in the local device communication protocol. An adjacent network attacker may intercept, replay or forge locally exchanged control messages, potentially resulting in unauthorized device control. Successful exploitation could allow an attacker to manipulate the operational state of an affected device, resulting in unauthorized state changes, disruption of normal device functionality or a denial-of-service condition.

CWE

Идентификатор Описание
CWE-325 The product does not implement a required step in a cryptographic algorithm, resulting in weaker encryption than advertised by the algorithm.

CVSS

Оценка Severity Версия Базовый вектор
8.7 HIGH 4.0 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Доп. Информация

Product Status

HS103P3 / HS103P4 v5
Product: HS103P3 / HS103P4 v5
Vendor: TP-Link Systems Inc.
Default status: unaffected
Версии:
Затронутые версии Статус
Наблюдалось в версиях от 0 до 1.1.3 Build 250908 Rel.112508 affected
EP10
Product: EP10
Vendor: TP-Link Systems Inc.
Default status: unaffected
Версии:
Затронутые версии Статус
Наблюдалось в версиях от 0 до 1.1.1 Build 250908 Rel.112508 affected
EP25 V2
Product: EP25 V2
Vendor: TP-Link Systems Inc.
Default status: unaffected
Версии:
Затронутые версии Статус
Наблюдалось в версиях от 0 до 1.0.3 Build 240529 Rel.145252 affected
HS300 V2
Product: HS300 V2
Vendor: TP-Link Systems Inc.
Default status: unaffected
Версии:
Затронутые версии Статус
Наблюдалось в версиях от 0 до 1.1.2 Build 241220 Rel.171333 affected
KP303 V2
Product: KP303 V2
Vendor: TP-Link Systems Inc.
Default status: unaffected
Версии:
Затронутые версии Статус
Наблюдалось в версиях от 0 до 1.1.2 Build 241220 Rel.173321 affected
EP40A
Product: EP40A
Vendor: TP-Link Systems Inc.
Default status: unaffected
Версии:
Затронутые версии Статус
Наблюдалось в версиях от 0 до 1.1.1 Build 250908 Rel.112526 affected
KP125MP2 / KP125MP4
Product: KP125MP2 / KP125MP4
Vendor: TP-Link Systems Inc.
Default status: unaffected
Версии:
Затронутые версии Статус
Наблюдалось в версиях от 0 до 1.2.5 Build 241213 Rel.172504 affected
KP115
Product: KP115
Vendor: TP-Link Systems Inc.
Default status: unaffected
Версии:
Затронутые версии Статус
Наблюдалось в версиях от 0 до 1.1.1 Build 250908 Rel.112945 affected
KS225
Product: KS225
Vendor: TP-Link Systems Inc.
Default status: unaffected
Версии:
Затронутые версии Статус
Наблюдалось в версиях от 0 до 1.1.1 Build 240626 Rel.175125 affected
EP40M
Product: EP40M
Vendor: TP-Link Systems Inc.
Default status: unaffected
Версии:
Затронутые версии Статус
Наблюдалось в версиях от 0 до 1.1.0 Build 240415 Rel.171219 affected
KS205
Product: KS205
Vendor: TP-Link Systems Inc.
Default status: unaffected
Версии:
Затронутые версии Статус
Наблюдалось в версиях от 0 до 1.1.1 Build 240724 Rel.105920 affected
KS240
Product: KS240
Vendor: TP-Link Systems Inc.
Default status: unaffected
Версии:
Затронутые версии Статус
Наблюдалось в версиях от 0 до 1.0.6 Build 240122 Rel.160100 affected
ES20M
Product: ES20M
Vendor: TP-Link Systems Inc.
Default status: unaffected
Версии:
Затронутые версии Статус
Наблюдалось в версиях от 0 до 1.1.6 Build 250522 Rel.210254 affected
KS220M
Product: KS220M
Vendor: TP-Link Systems Inc.
Default status: unaffected
Версии:
Затронутые версии Статус
Наблюдалось в версиях от 0 до 1.1.6 Build 250522 Rel.210254 affected
KP200 V3
Product: KP200 V3
Vendor: TP-Link Systems Inc.
Default status: unaffected
Версии:
Затронутые версии Статус
Наблюдалось в версиях от 0 до 1.1.0 Build 250225 Rel.171724 affected
HS200 V5.26
Product: HS200 V5.26
Vendor: TP-Link Systems Inc.
Default status: unaffected
Версии:
Затронутые версии Статус
Наблюдалось в версиях от 0 до 1.0.3 Build 240723 Rel.192622 affected
HS220-LA(US) 6.6 / HS220-BL(US) 6.6
Product: HS220-LA(US) 6.6 / HS220-BL(US) 6.6
Vendor: TP-Link Systems Inc.
Default status: unaffected
Версии:
Затронутые версии Статус
Наблюдалось в версиях от 0 до 1.0.3 Build 240723 Rel.192630 affected
HS220 V3.26
Product: HS220 V3.26
Vendor: TP-Link Systems Inc.
Default status: unaffected
Версии:
Затронутые версии Статус
Наблюдалось в версиях от 0 до 1.1.1 Build 240802 Rel.094131 affected
HS220-LA(US) 4.6 / HS220-BL(US) 4.6
Product: HS220-LA(US) 4.6 / HS220-BL(US) 4.6
Vendor: TP-Link Systems Inc.
Default status: unaffected
Версии:
Затронутые версии Статус
Наблюдалось в версиях от 0 до 1.1.1 Build 240802 Rel.094142 affected
KL125
Product: KL125
Vendor: TP-Link Systems Inc.
Default status: unaffected
Версии:
Затронутые версии Статус
Наблюдалось в версиях от 0 до 1.1.1 Build 260710 Rel.082646 affected
 

Ссылки

CISA ADP Vulnrichment

Обновлено: 26.08.2026
Этот блок содержит дополнительную информацию, предоставленную программой CVE для этой уязвимости.

SSVC

Exploitation Automatable Technical Impact Версия Дата доступа
none no total 2.0.3 26.08.2026

Мы используем cookie-файлы, чтобы получить статистику, которая помогает нам улучшить сервис для вас с целью персонализации сервисов и предложений. Вы может прочитать подробнее о cookie-файлах или изменить настройки браузера. Продолжая пользоваться сайтом, вы даёте согласие на использование ваших cookie-файлов и соглашаетесь с Политикой обработки персональных данных.