TP-Link has disclosed two security vulnerabilities affecting its Kasa EC70 v4 and EC71 v4 smart camera models, which could let attackers on the same local network intercept administrative credentials and extract sensitive geolocation data.
The more severe flaw, tracked as CVE-2026-9770, stems from a hardcoded cryptographic key embedded directly in the device’s system image.
This hardware-level exposure undermines the confidentiality of communications between the camera and its web management interface.
TP-Link Kasa Camera Flaws
An attacker on the same local network can exploit this weakness to conduct man-in-the-middle (MITM) attacks, intercept traffic, and potentially harvest administrator login credentials.
Because the key is baked into the firmware rather than generated per-device, every unpatched unit shares the same cryptographic weakness, making exploitation straightforward for anyone with local network access.
TP-Link rated this issue 8.6 (High) under CVSS v4.0, with the vector CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N reflecting low attack complexity, no privileges required, and high impact to both confidentiality and integrity.
The second vulnerability, CVE-2026-13230, resides in the camera’s local discovery mechanism. This feature, typically used for device pairing and network setup, responds to discovery requests without requiring any authentication.
Attackers on the same LAN can send crafted discovery requests to extract geolocation-related information tied to the device, no login credentials or user interaction needed.
While this issue affects confidentiality only, with no impact on integrity or availability, exposed location data still carries real privacy risk, particularly for indoor or outdoor security cameras deployed in homes and businesses.
This flaw earned a 5.3 (Medium) severity score, with vector CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N.
Affected Devices and Fixes
Both vulnerabilities affect the following models:
- Kasa EC70 v4 — fixed in firmware 2.4.0 Build 20260520 rel.4191
- Kasa EC71 v4 — fixed in firmware 2.4.1 Build 20260621 rel.76536
TP-Link has released patched firmware for both models and strongly recommends that users update immediately via the official support pages and update the companion Kasa mobile app to ensure compatibility with the patched builds.
Mitigation
Both flaws require local network access, which somewhat limits remote exploitation but does not eliminate risk. Shared Wi-Fi networks, compromised IoT devices, or malicious actors on guest networks could all serve as launch points for these attacks.
Given that consumer security cameras often sit on the same network as other smart home devices, a single compromised device could open the door to lateral movement and credential theft across a household’s entire IoT ecosystem.
Users running EC70 v4 or EC71 v4 cameras should treat this update as a high priority, particularly given how easily an attacker can exploit it once they gain local network access.
Prevent critical incidents and financial loss with stronger proactive defense. Integrate a live threat feed from 15K SOCs