TP-Link has revealed several serious vulnerabilities affecting its Kasa EC70 and EC71 smart camera models, which could expose users to credential theft and geolocation data leakage.
These vulnerabilities are CVE-2026-9770 and CVE-2026-13230 and specifically affect version 4 of both devices. Attackers with access to the same local network could exploit these flaws, raising concerns about lateral movement risks in both home and enterprise environments.
TP-Link Kasa Camera Flaws
The most critical issue, CVE-2026-9770, is a hardware cryptographic key disclosure vulnerability caused by a hardcoded key embedded in the device firmware.
This flaw allows attackers to decrypt communications between the camera and its web management interface, effectively undermining transport security measures.
By exploiting this vulnerability, a threat actor on the local network could conduct man-in-the-middle (MITM) attacks to intercept sensitive traffic, including administrative credentials.
This vulnerability has a CVSS v4.0 score of 8.6, indicating a high impact on confidentiality and integrity, with no privileges required and no user interaction needed for exploitation.
In addition, CVE-2026-13230 exposes sensitive geolocation data through the device’s unauthenticated local discovery mechanism. This flaw enables attackers to send crafted discovery requests and access location-related metadata without authentication.
Although this vulnerability does not compromise system integrity or availability, it poses privacy risks by allowing attackers to map device locations and potentially profile users.
This issue has a CVSS v4.0 score of 5.3, indicating medium severity. However, it remains significant in scenarios where location data could be leveraged for targeted attacks or surveillance.
Both vulnerabilities specifically affect Kasa EC70 v4 and EC71 v4 devices running firmware versions before 2.4.0 Build 20260520 rel. 4191 and 2.4.1 Build 20260621 rel. 76536.
TP-Link has released patched firmware that addresses both flaws and strongly urges users to upgrade immediately to mitigate their exposure. The company also recommends updating the Kasa mobile application to ensure compatibility with the latest security fixes.
While exploitation requires access to the local network, these vulnerabilities could be combined with other network footholds, such as compromised IoT devices or weak Wi-Fi security, to broaden an attacker’s capabilities.
The existence of a hardcoded cryptographic key is particularly concerning, as it reflects a systemic design flaw that bypasses standard encryption safeguards.
Security experts emphasize that IoT devices remain a critical attack surface due to inconsistent security practices and delayed patch adoption.
Users are advised to isolate IoT devices on separate network segments, enforce strong wireless security configurations, and monitor for anomalous traffic patterns.
Timely firmware updates are the most effective way to mitigate these vulnerabilities, as unpatched devices may continue to expose sensitive data and administrative access to adversaries operating within the same network environment.
Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.





