CVE-2026-9770
Awaiting Analysis Awaiting Analysis - Queue

Static Cryptographic Key in Kasa EC71/EC70 Firmware

Vulnerability report for CVE-2026-9770, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-15

Last updated on: 2026-07-15

Assigner: TPLink

Description

Kasa EC71 v4 and EC70 v4 firmware contains a static cryptographic private key stored in a read-only filesystem that is shared across devices.Β  An attacker with access to the firmware image can extract the embedded key.Β  Successful exploitation may allow an unauthenticated attacker on the same network to use this key in the web management service, compromising the confidentiality of encrypted communications. This may enable passive decryption of traffic or active man-in-the-middle (MITM) attacks

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-15
Last Modified
2026-07-15
Generated
2026-08-04
AI Q&A
2026-07-15
EPSS Evaluated
2026-08-02
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
tp-link kasa_ec70 v4
tp-link kasa_ec71 v4

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-321 The product uses a hard-coded, unchangeable cryptographic key.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves TP-Link Kasa EC70 v4 and EC71 v4 devices using a static cryptographic private key stored in their firmware. The key is shared across all devices, allowing attackers who obtain the firmware to extract it. This enables unauthorized decryption of network traffic or man-in-the-middle attacks.

Detection Guidance

Detecting this vulnerability requires checking for the presence of the static cryptographic private key in the firmware of Kasa EC70 v4 or EC71 v4 devices. Inspect the firmware image for hardcoded keys or use network monitoring tools to detect unauthorized decryption of traffic.

Impact Analysis

This vulnerability may allow an unauthenticated attacker on the same network to use the extracted key in the web management service, compromising encrypted communications. This could enable passive decryption of traffic or active man-in-the-middle attacks.

Compliance Impact

This vulnerability may compromise compliance with GDPR and HIPAA due to the risk of unauthorized decryption of sensitive data. The static cryptographic key allows attackers to intercept and decrypt encrypted communications, potentially exposing personal or health information.

Mitigation Strategies
  • Check TP-Link's security advisory for official patches or updates for EC70 v4 and EC71 v4 devices.
  • Isolate affected devices from sensitive networks to prevent MITM attacks.
  • Monitor network traffic for unusual decryption attempts or unauthorized access.
  • Replace or update firmware if patches are available from TP-Link.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-9770. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart