TP-Link Kasa EC70 and EC71 Flaws Let Local Attackers Steal Admin Credentials and Leak Camera Location
Home cameras rarely stray beyond the local network. Nevertheless, vulnerabilities in the TP-Link Kasa EC70 and EC71 allow an attacker already inside that network to intercept administrator credentials and glean the device’s location.
CVE-2026-9770: A Hardcoded Key Opens the Door
The most dangerous vulnerability, CVE-2026-9770, earned a score of 8.6 on the CVSS 4.0 scale. A hardcoded cryptographic key resides within the cameras’ firmware. An attacker can extract that key, decrypt the traffic between the camera and its web management interface, and then mount a man-in-the-middle attack to capture administrative data. Exploitation requires no system privileges and no action by the owner. However, the attacker must reside on the same local network.
CVE-2026-13230: Leaking the Camera’s Whereabouts
The second vulnerability, CVE-2026-13230, scored 5.3 on the CVSS 4.0 scale. It exposes geolocation information through the local device-discovery mechanism. A specially crafted request retrieves location-related metadata without authorization. The flaw cannot alter the camera’s operation or disable the device. Even so, it can help an intruder map where cameras are placed and gather details about their owners.
Affected Versions and the Fix
The problems affect the Kasa EC70 v4 running firmware earlier than 2.4.0 Build 20260520 rel. 4191, and the EC71 v4 with versions prior to 2.4.1 Build 20260621 rel. 76536. TP-Link has already released patched firmware and also recommends updating the Kasa mobile application.
How to Reduce Your Risk
The entire risk is confined to the local network. Nevertheless, access to that network could arrive through any other compromised IoT device or weak Wi-Fi security. Camera owners are therefore advised to install the latest firmware, move their Internet of Things devices onto a separate network segment, strengthen wireless protection, and watch for unusual traffic.
Support Our Threat Intelligence
If you find our technology report and cybersecurity news helpful, consider supporting our work.