CVE-2026-9770: Hardcoded Cryptographic Key Information Disclosure Vulnerability on TP-Link Kasa EC70 and EC71

Published Jul 15, 2026
·
Updated

Kasa EC71 v4 and EC70 v4 firmware contains a static cryptographic private key stored in a read-only filesystem that is shared across devices.  An attacker with access to the firmware image can extract the embedded key.

Successful exploitation may allow an unauthenticated attacker on the same network to use this key in the web management service, compromising the confidentiality of encrypted communications. This may enable passive decryption of traffic or active man-in-the-middle (MITM) attacks

Affected Software

2 affected components
TP-Link Kasa EC71<=v4
TP-Link Kasa EC70<=v4

Event History

Jul 15, 2026
CVE Published
via MITRE·12:21 AM
Data Sourced
via MITRE·12:21 AM
DescriptionWeakness
Data Sourced
via NVD·01:17 AM
DescriptionSeverityWeakness
Apr 11, 58531
Event
via FIRST·10:11 AM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-9770?

CVE-2026-9770 has a high severity rating of 8.6.

2

How do I fix CVE-2026-9770?

To mitigate CVE-2026-9770, update the firmware of the TP-Link Kasa EC70 and EC71 devices to the latest version provided by the manufacturer.

3

What are the potential risks associated with CVE-2026-9770?

CVE-2026-9770 may allow an attacker on the same network to extract a hardcoded cryptographic key, leading to information disclosure.

4

Which devices are affected by CVE-2026-9770?

CVE-2026-9770 affects TP-Link Kasa EC70 and EC71 devices, specifically version 4 firmware.

5

Can CVE-2026-9770 be exploited remotely?

CVE-2026-9770 requires local network access, making remote exploitation not possible without initial network access.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203