CVE-2026-9770 Details
Description
Kasa EC71 v4 and EC70 v4 firmware contains a static cryptographic private key stored in a read-only filesystem that is shared across devices. An attacker with access to the firmware image can extract the embedded key. Successful exploitation may allow an unauthenticated attacker on the same network to use this key in the web management service, compromising the confidentiality of encrypted communications. This may enable passive decryption of traffic or active man-in-the-middle (MITM) attacks
A vulnerability exists in the Kasa EC70 v4 and EC71 v4 firmware due to a hardcoded cryptographic private key stored in a read-only filesystem, shared across devices. An attacker with access to the firmware image can extract this key. Exploitation may allow an unauthenticated attacker on the same network to use the key in the web management service, compromising the confidentiality of encrypted communications. This could lead to passive decryption of traffic or active man-in-the-middle attacks.
Users are advised to update to the latest firmware version. The patched version for the Kasa EC70 and EC71 is 2.4.0 Build 20260520 or 2.4.1 Build 20260621. Instructions for downloading the firmware are available on the TP-Link website.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 15, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.tp-link.com/en/support/download/ec70/v4/#Firmware-Release-Notes | TPLink | Release Notes |
| https://www.tp-link.com/en/support/download/ec71/v4/#Firmware-Release-Notes | TPLink | Release Notes |
| https://www.tp-link.com/us/support/download/ec70/v4/#Firmware-Release-Notes | TPLink | Release Notes |
| https://www.tp-link.com/us/support/download/ec71/v4/#Firmware-Release-Notes | TPLink | Release Notes |
| https://www.tp-link.com/us/support/faq/5192/ | TPLink | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-321 | Use of Hard-coded Cryptographic Key | TPLink |
Affected Products
| Product | Versions |
|---|---|
| tp-link kasa ec71 firmware | < 2.4.0 |
CPE
Remediation
| |
| tp-link kasa ec71 | 4.0 |
CPE
Remediation
| |
| tp-link kasa ec70 firmware | < 2.4.0 |
CPE
Remediation
| |
| tp-link kasa ec70 | 4.0 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 6, 2026 | Initial Analysis | [email protected] |
| Jul 15, 2026 | CVE Modified | CISA-ADP |
| Jul 15, 2026 | New CVE Received | TPLink |