logo

TP-Link Kasa Camera Flaws Let Attackers Steal Admin Credentials and Geolocation Data

ID: d9b87fbf-c747-5047-9ab2-8db7bef37f4d

STIX ID: report--d9b87fbf-c747-5047-9ab2-8db7bef37f4d

Feed Name: GBHackers

Threat Score
70/100

Date Published: 2026-07-17

Date Updated: 2026-07-17

Author: Divya

...
...

TP-Link disclosed two vulnerabilities affecting Kasa EC70 v4 and EC71 v4 cameras: CVE-2026-9770 (CVSS v4.0 8.6) is a hardcoded cryptographic key in firmware that allows local attackers to decrypt web management traffic and capture administrative credentials via MITM, and CVE-2026-13230 (CVSS v4.0 5.3) enables unauthenticated local discovery to leak geolocation metadata; both issues impact devices running firmware before the listed builds, patched firmware is available, and users are urged to update and isolate IoT devices to mitigate lateral-movement and privacy risks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.