Description
Kasa EC71 v4 and EC70 v4 firmware contains a static cryptographic private key stored in a read-only filesystem
that is shared across devices.  An
attacker with access to the firmware image can extract the embedded key. 









Successful
exploitation may allow an unauthenticated attacker on the same network to use
this key in the web management service, compromising the confidentiality of
encrypted communications. This may enable passive decryption of traffic or
active man-in-the-middle (MITM) attacks
Published: 2026-07-15
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The firmware for TP‑Link Kasa EC70 v4 and EC71 v4 contains a static cryptographic private key stored on a read‑only filesystem that is shared across all units. An attacker who can examine the firmware image can extract this key, and then use it to compromise the confidentiality of the appliance’s HTTPS traffic. Successful use of the key allows passive decryption of inbound messages or an active man‑in‑the‑middle attack against the web management interface.

Affected Systems

TP‑Link Systems – Kasa EC70 version 4 and TP‑Link Systems – Kasa EC71 version 4 are affected. Devices flashing these firmware releases expose the hard‑coded key and are vulnerable to key extraction.

Risk and Exploitability

The CVSS score of 8.6 reflects high severity, yet the EPSS score of less than 1 % indicates a low probability of real‑world exploitation, and the vulnerability is currently not listed in CISA KEV. Exploitation requires an attacker to obtain the firmware image or gain unauthenticated access to the device’s web interface; once the key is extracted, the attacker can decrypt traffic or perform MITM attacks against encrypted communications.

Generated by OpenCVE AI on July 31, 2026 at 04:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the device firmware to the latest version available from TP‑Link, which removes the hard‑coded key.
  • If an update is unavailable, isolate the appliance on a separate VLAN or subnet that only trusted users can reach, thereby preventing unauthenticated local attackers from accessing the web management interface.
  • Configure firewall or router rules to block external access to the web management ports (commonly 80/443) so that only internal management traffic is allowed.

Generated by OpenCVE AI on July 31, 2026 at 04:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
First Time appeared Tp-link
Tp-link kasa Ec70 V4
Tp-link kasa Ec71 V4
Vendors & Products Tp-link
Tp-link kasa Ec70 V4
Tp-link kasa Ec71 V4

Wed, 15 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 15 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
Description Kasa EC71 v4 and EC70 v4 firmware contains a static cryptographic private key stored in a read-only filesystem that is shared across devices.  An attacker with access to the firmware image can extract the embedded key.  Successful exploitation may allow an unauthenticated attacker on the same network to use this key in the web management service, compromising the confidentiality of encrypted communications. This may enable passive decryption of traffic or active man-in-the-middle (MITM) attacks
Title Hardcoded Cryptographic Key Information Disclosure Vulnerability on TP-Link Kasa EC70 and EC71
Weaknesses CWE-321
References
Metrics cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Tp-link Kasa Ec70 V4 Kasa Ec71 V4
cve-icon MITRE

Status: PUBLISHED

Assigner: TPLink

Published:

Updated: 2026-07-15T12:38:03.180Z

Reserved: 2026-05-27T22:00:46.491Z

Link: CVE-2026-9770

cve-icon Vulnrichment

Updated: 2026-07-15T12:37:58.892Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T04:15:04Z

Weaknesses
  • CWE-321

    Use of Hard-coded Cryptographic Key