CVE-2026-9770

HIGH CVSS 4.0: 8.6 EPSS 0.36%
Updated Aug 06, 2026
Tp-Link Systems Inc.
Parameter Value
CVSS 8.6 (HIGH)
Affected Versions before 2.4.0
Fixed In 2.4.0
Type CWE-321
Vendor Tp-Link Systems Inc.
Public PoC No

Kasa EC71 v4 and EC70 v4 firmware contains a static cryptographic private key stored in a read-only filesystem that is shared across devices. An attacker with access to the firmware image can extract the embedded key. Successful exploitation may allow an unauthenticated attacker on the same network to use this key in the web management service, compromising the confidentiality of encrypted communications.

This may enable passive decryption of traffic or active man-in-the-middle (MITM) attacks

Attack Parameters

Attack Vector
Adjacent
Requires local network access
Attack Complexity
Low
Easy to exploit
Attack Requirements
None
No additional conditions
Privileges Required
None
No privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
High
Complete data modification
Availability
None
No disruption

CVSS Vector v4.0

Weakness Type (CWE)

Vulnerable Products 4

Configuration From (including) Up to (excluding)
Tp-Link Kasa_Ec71_Firmware
cpe:2.3:o:tp-link:kasa_ec71_firmware:*:*:*:*:*:*:*:*
2.4.0
Tp-Link Kasa_Ec71
cpe:2.3:h:tp-link:kasa_ec71:4.0:*:*:*:*:*:*:*
Tp-Link Kasa_Ec70_Firmware
cpe:2.3:o:tp-link:kasa_ec70_firmware:*:*:*:*:*:*:*:*
2.4.0
Tp-Link Kasa_Ec70
cpe:2.3:h:tp-link:kasa_ec70:4.0:*:*:*:*:*:*:*