TP-Link: Multiple TP-Link Cameras Vulnerability Allows Hackers to Launch MitM Attacks

TP-Link: Multiple TP-Link Cameras Vulnerability Allows Hackers to Launch MitM Attacks

TP-Link Patches High-Severity Vulnerabilities in Kasa Smart Cameras

TP-Link has released security updates for two vulnerabilities in its Kasa EC70 v4 and EC71 v4 smart cameras, which could allow attackers on the same local network to access sensitive data.

The most critical flaw, CVE-2026-9770 (CVSS 8.6), involves a hardcoded cryptographic key embedded in the camera’s firmware. Exploitation could enable man-in-the-middle (MitM) attacks, allowing threat actors to intercept communications, steal administrative credentials, or manipulate traffic. Attackers could leverage this on shared Wi-Fi networks, compromised routers, or poorly segmented office networks.

The second vulnerability, CVE-2026-13230 (CVSS 5.3), affects the cameras’ local discovery mechanism, exposing geolocation-related data without authentication. While this flaw only impacts confidentiality, it could still aid attackers in reconnaissance.

Both issues have been patched in firmware versions 2.4.0 Build 20260520 and 2.4.1 Build 20260621. TP-Link advises users to update via the Kasa app or official support portal and recommends network segmentation to mitigate risks until patches are applied. Unpatched devices remain vulnerable to exploitation.

Source: https://cybersecuritynews.com/tp-link-cameras-vulnerability/

TP-Link Systems Inc. cybersecurity rating report: https://www.rankiteo.com/company/tp-link

"id": "TP-1784276626",
"linkid": "tp-link",
"type": "Vulnerability",
"date": "5/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'industry': 'Technology (Smart Home Devices)',
                        'name': 'TP-Link',
                        'type': 'Company'}],
 'attack_vector': 'Local Network',
 'customer_advisories': 'Update firmware via Kasa app or official support '
                        'portal and apply network segmentation.',
 'data_breach': {'sensitivity_of_data': 'High (credentials), Medium '
                                        '(geolocation)',
                 'type_of_data_compromised': 'Administrative credentials, '
                                             'geolocation-related data'},
 'description': 'TP-Link has released security updates for two vulnerabilities '
                'in its Kasa EC70 v4 and EC71 v4 smart cameras, which could '
                'allow attackers on the same local network to access sensitive '
                'data. The most critical flaw, CVE-2026-9770 (CVSS 8.6), '
                'involves a hardcoded cryptographic key embedded in the '
                'camera’s firmware, enabling man-in-the-middle (MitM) attacks. '
                'The second vulnerability, CVE-2026-13230 (CVSS 5.3), exposes '
                'geolocation-related data without authentication.',
 'impact': {'data_compromised': 'Sensitive data, administrative credentials, '
                                'geolocation-related data',
            'systems_affected': 'Kasa EC70 v4 and EC71 v4 smart cameras'},
 'investigation_status': 'Patched',
 'post_incident_analysis': {'corrective_actions': 'Firmware updates to remove '
                                                  'hardcoded keys and secure '
                                                  'local discovery',
                            'root_causes': 'Hardcoded cryptographic key, '
                                           'unauthenticated local discovery '
                                           'mechanism'},
 'recommendations': 'Update firmware immediately, implement network '
                    'segmentation, and monitor for suspicious activity on '
                    'local networks.',
 'references': [{'source': 'TP-Link Security Advisory'}],
 'response': {'communication_strategy': 'Advisory to update firmware and '
                                        'recommendations for network '
                                        'segmentation',
              'containment_measures': 'Firmware updates (versions 2.4.0 Build '
                                      '20260520 and 2.4.1 Build 20260621)',
              'network_segmentation': 'Recommended as mitigation',
              'remediation_measures': 'Patching via Kasa app or official '
                                      'support portal'},
 'title': 'TP-Link Patches High-Severity Vulnerabilities in Kasa Smart Cameras',
 'type': 'Vulnerability Exploitation',
 'vulnerability_exploited': ['CVE-2026-9770', 'CVE-2026-13230']}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.