Saturday, August 29, 2026

TP-Link Kasa Camera Flaws Let Attackers Steal Admin Credentials and Geolocation Data

TP-Link has revealed several serious vulnerabilities affecting its Kasa EC70 and EC71 smart camera models, which could expose users to credential theft and geolocation data leakage.

These vulnerabilities are CVE-2026-9770 and CVE-2026-13230 and specifically affect version 4 of both devices. Attackers with access to the same local network could exploit these flaws, raising concerns about lateral movement risks in both home and enterprise environments.

The most critical issue, CVE-2026-9770, is a hardware cryptographic key disclosure vulnerability caused by a hardcoded key embedded in the device firmware.

This flaw allows attackers to decrypt communications between the camera and its web management interface, effectively undermining transport security measures.

By exploiting this vulnerability, a threat actor on the local network could conduct man-in-the-middle (MITM) attacks to intercept sensitive traffic, including administrative credentials.

This vulnerability has a CVSS v4.0 score of 8.6, indicating a high impact on confidentiality and integrity, with no privileges required and no user interaction needed for exploitation.

In addition, CVE-2026-13230 exposes sensitive geolocation data through the device’s unauthenticated local discovery mechanism. This flaw enables attackers to send crafted discovery requests and access location-related metadata without authentication.

Although this vulnerability does not compromise system integrity or availability, it poses privacy risks by allowing attackers to map device locations and potentially profile users.

This issue has a CVSS v4.0 score of 5.3, indicating medium severity. However, it remains significant in scenarios where location data could be leveraged for targeted attacks or surveillance.

Both vulnerabilities specifically affect Kasa EC70 v4 and EC71 v4 devices running firmware versions before 2.4.0 Build 20260520 rel. 4191 and 2.4.1 Build 20260621 rel. 76536.

TP-Link has released patched firmware that addresses both flaws and strongly urges users to upgrade immediately to mitigate their exposure. The company also recommends updating the Kasa mobile application to ensure compatibility with the latest security fixes.

While exploitation requires access to the local network, these vulnerabilities could be combined with other network footholds, such as compromised IoT devices or weak Wi-Fi security, to broaden an attacker’s capabilities.

The existence of a hardcoded cryptographic key is particularly concerning, as it reflects a systemic design flaw that bypasses standard encryption safeguards.

Security experts emphasize that IoT devices remain a critical attack surface due to inconsistent security practices and delayed patch adoption.

Users are advised to isolate IoT devices on separate network segments, enforce strong wireless security configurations, and monitor for anomalous traffic patterns.

Timely firmware updates are the most effective way to mitigate these vulnerabilities, as unpatched devices may continue to expose sensitive data and administrative access to adversaries operating within the same network environment.

 Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Hackers Compromise TanStack Query npm Package to Steal Developer Credentials

A supply-chain worm has compromised multiple releases of @7nohe/openapi-react-query-codegen,...

Critical Gogs Flaw Enables Remote Code Execution Through Path Traversal

A critical vulnerability in Gogs, the self-hosted Git service,...

Hackers Use Fake Cloudflare CAPTCHA to Deploy TerminalFix Reverse Tunnel

A newly documented TerminalFix campaign is using fake Cloudflare...

Chinese Hackers Deploy PackClient RAT via Tax-Themed Phishing Attacks to Steal Data

A Chinese-speaking threat actor tracked as TA4922 is deploying...

Attackers Exploit MCP RCE, Blind Prompt Injection and Memory Credential Theft Against AI Infrastructure

Attackers are increasingly treating AI infrastructure as a high-value...

700 OpenAI Agents Coordinate Attack on Hugging Face and Gain Remote Code Execution

OpenAI’s ExploitGym evaluation environment reportedly became the site of...

Polymorphic Phishing Attack Generates Unique Credential-Stealing Page on Every Visit

A newly analyzed phishing operation is using server-side polymorphism...

Critical WordPress Plugin Flaw Allows Unauthenticated Administrator Account Takeover

A critical authentication bypass vulnerability has been identified in...

Related Articles

Recent News