TP-Link has patched two vulnerabilities in Kasa EC70 v4 and EC71 v4 cameras, including the high-severity CVE-2026-9770 flaw caused by a hardcoded private cryptographic key embedded in firmware. Because the same static key was stored in a read-only filesystem and shared across devices, an unauthenticated attacker on the same local network could extract it from the firmware image and use it against the cameras’ web management service, undermining the confidentiality of encrypted communications. The issue could enable passive traffic decryption, machine-in-the-middle interception, and capture of administrative credentials.
TP-Link also fixed CVE-2026-13230, a lower-severity information disclosure bug that can reveal geolocation data through the devices’ local discovery mechanism without authentication. The affected products are vulnerable on firmware versions earlier than 2.4.0 Build 20260520 rel.4191, and the company said it has found no evidence of active exploitation or any public proof-of-concept. Because both flaws require local network access, the exposure is most relevant to shared Wi-Fi environments or compromised devices already inside the network; users are advised to update camera firmware and the Kasa mobile app and to isolate IoT devices on a guest or segmented network.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
Subsequent reporting said TP-Link had also patched CVE-2026-13230, which can expose geolocation data through local discovery without authentication. TP-Link said it had found no evidence of in-the-wild exploitation and that no public proof-of-concept was available.
A hardcoded private key vulnerability affecting TP-Link Kasa EC70 v4 and EC71 v4 cameras was publicly disclosed as CVE-2026-9770. The flaw could let an unauthenticated attacker on the same network decrypt communications or conduct man-in-the-middle attacks against the web management service.
TP-Link patched two information disclosure vulnerabilities affecting Kasa EC70 v4 and EC71 v4 cameras, including CVE-2026-9770 and CVE-2026-13230. The fixes are present in firmware versions 2.4.0 Build 20260520 rel.4191 and later for the affected products.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcesecurityonline.info
Open sourcecvefeed.io
Open sourcetp-link.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.