Multiple TP-Link Cameras Vulnerability Allows Hackers to Launch MitM Attacks
ID: 984fc8ac-448f-5d97-bceb-2d136e6b514f
STIX ID: report--984fc8ac-448f-5d97-bceb-2d136e6b514f
Feed Name: cybersecurityNews.com
TP-Link released firmware fixes for two vulnerabilities in Kasa EC70 v4 and EC71 v4 cameras: CVE-2026-9770 (High, CVSS 8.6) involving a hardcoded cryptographic key that can enable local network attackers to perform man-in-the-middle attacks and access admin credentials, and CVE-2026-13230 (Medium, CVSS 5.3) where the local discovery service can leak geolocation-related information without authentication. TP-Link provided patched firmware (2.4.0 Build 20260520 and 2.4.1 Build 20260621) and recommends updating device firmware and the Kasa app, isolating cameras on segmented IoT networks, and hardening routers until patches are applied.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
