Impact
The firmware for TP‑Link Kasa EC70 v4 and EC71 v4 contains a static cryptographic private key stored on a read‑only filesystem that is shared across all units. An attacker who can examine the firmware image can extract this key, and then use it to compromise the confidentiality of the appliance’s HTTPS traffic. Successful use of the key allows passive decryption of inbound messages or an active man‑in‑the‑middle attack against the web management interface.
Affected Systems
TP‑Link Systems – Kasa EC70 version 4 and TP‑Link Systems – Kasa EC71 version 4 are affected. Devices flashing these firmware releases expose the hard‑coded key and are vulnerable to key extraction.
Risk and Exploitability
The CVSS score of 8.6 reflects high severity, yet the EPSS score of less than 1 % indicates a low probability of real‑world exploitation, and the vulnerability is currently not listed in CISA KEV. Exploitation requires an attacker to obtain the firmware image or gain unauthenticated access to the device’s web interface; once the key is extracted, the attacker can decrypt traffic or perform MITM attacks against encrypted communications.
OpenCVE Enrichment