Cyber Security News

TP-Link Kasa Camera Flaws Let Attackers Steal Admin Credentials and Geolocation Data

TP-Link has revealed several serious vulnerabilities affecting its Kasa EC70 and EC71 smart camera models, which could expose users to credential theft and geolocation data leakage.

These vulnerabilities are CVE-2026-9770 and CVE-2026-13230 and specifically affect version 4 of both devices. Attackers with access to the same local network could exploit these flaws, raising concerns about lateral movement risks in both home and enterprise environments.

The most critical issue, CVE-2026-9770, is a hardware cryptographic key disclosure vulnerability caused by a hardcoded key embedded in the device firmware.

This flaw allows attackers to decrypt communications between the camera and its web management interface, effectively undermining transport security measures.

By exploiting this vulnerability, a threat actor on the local network could conduct man-in-the-middle (MITM) attacks to intercept sensitive traffic, including administrative credentials.

This vulnerability has a CVSS v4.0 score of 8.6, indicating a high impact on confidentiality and integrity, with no privileges required and no user interaction needed for exploitation.

In addition, CVE-2026-13230 exposes sensitive geolocation data through the device’s unauthenticated local discovery mechanism. This flaw enables attackers to send crafted discovery requests and access location-related metadata without authentication.

Although this vulnerability does not compromise system integrity or availability, it poses privacy risks by allowing attackers to map device locations and potentially profile users.

This issue has a CVSS v4.0 score of 5.3, indicating medium severity. However, it remains significant in scenarios where location data could be leveraged for targeted attacks or surveillance.

Both vulnerabilities specifically affect Kasa EC70 v4 and EC71 v4 devices running firmware versions before 2.4.0 Build 20260520 rel. 4191 and 2.4.1 Build 20260621 rel. 76536.

TP-Link has released patched firmware that addresses both flaws and strongly urges users to upgrade immediately to mitigate their exposure. The company also recommends updating the Kasa mobile application to ensure compatibility with the latest security fixes.

While exploitation requires access to the local network, these vulnerabilities could be combined with other network footholds, such as compromised IoT devices or weak Wi-Fi security, to broaden an attacker’s capabilities.

The existence of a hardcoded cryptographic key is particularly concerning, as it reflects a systemic design flaw that bypasses standard encryption safeguards.

Security experts emphasize that IoT devices remain a critical attack surface due to inconsistent security practices and delayed patch adoption.

Users are advised to isolate IoT devices on separate network segments, enforce strong wireless security configurations, and monitor for anomalous traffic patterns.

Timely firmware updates are the most effective way to mitigate these vulnerabilities, as unpatched devices may continue to expose sensitive data and administrative access to adversaries operating within the same network environment.

 Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.

Divya

Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Recent Posts

Hackers Compromise TanStack Query npm Package to Steal Developer Credentials

A supply-chain worm has compromised multiple releases of @7nohe/openapi-react-query-codegen, an npm package that generates type-safe…

5 hours ago

Critical Gogs Flaw Enables Remote Code Execution Through Path Traversal

A critical vulnerability in Gogs, the self-hosted Git service, could allow authenticated attackers to execute…

5 hours ago

Hackers Use Fake Cloudflare CAPTCHA to Deploy TerminalFix Reverse Tunnel

A newly documented TerminalFix campaign is using fake Cloudflare CAPTCHA prompts to trick users into…

6 hours ago

Chinese Hackers Deploy PackClient RAT via Tax-Themed Phishing Attacks to Steal Data

A Chinese-speaking threat actor tracked as TA4922 is deploying the PackClient remote access trojan via…

6 hours ago

Attackers Exploit MCP RCE, Blind Prompt Injection and Memory Credential Theft Against AI Infrastructure

Attackers are increasingly treating AI infrastructure as a high-value cloud entry point, exploiting exposed Model…

24 hours ago

700 OpenAI Agents Coordinate Attack on Hugging Face and Gain Remote Code Execution

OpenAI’s ExploitGym evaluation environment reportedly became the site of a large-scale, unsanctioned multi-agent campaign after…

1 day ago