{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-9770","assignerOrgId":"f23511db-6c3e-4e32-a477-6aa17d310630","state":"PUBLISHED","assignerShortName":"TPLink","dateReserved":"2026-05-27T22:00:46.491Z","datePublished":"2026-07-15T00:21:06.126Z","dateUpdated":"2026-07-15T12:38:03.180Z"},"containers":{"cna":{"providerMetadata":{"orgId":"f23511db-6c3e-4e32-a477-6aa17d310630","shortName":"TPLink","dateUpdated":"2026-07-15T00:21:06.126Z"},"title":"Hardcoded Cryptographic Key Information Disclosure Vulnerability on TP-Link Kasa EC70 and EC71","problemTypes":[{"descriptions":[{"lang":"en","cweId":"CWE-321","description":"CWE-321 Use of hard-coded cryptographic key","type":"CWE"}]}],"impacts":[{"capecId":"CAPEC-474","descriptions":[{"lang":"en","value":"CAPEC-474 Signature Spoofing by Key Theft"}]}],"affected":[{"vendor":"TP-Link Systems Inc.","product":"Kasa EC71 v4","versions":[{"status":"affected","version":"0","lessThan":"2.4.0 Build 20260520 rel.4191","versionType":"custom"}],"defaultStatus":"unaffected"},{"vendor":"TP-Link Systems Inc.","product":"Kasa EC70 v4","versions":[{"status":"affected","version":"0","lessThan":"2.4.0 Build 20260520 rel.4191","versionType":"custom"}],"defaultStatus":"unaffected"}],"descriptions":[{"lang":"en","value":"Kasa EC71 v4 and EC70 v4 firmware contains a static cryptographic private key stored in a read-only filesystem\nthat is shared across devices.  An\nattacker with access to the firmware image can extract the embedded key.  \n\n\n\n\n\n\n\n\n\nSuccessful\nexploitation may allow an unauthenticated attacker on the same network to use\nthis key in the web management service, compromising the confidentiality of\nencrypted communications. This may enable passive decryption of traffic or\nactive man-in-the-middle (MITM) attacks","supportingMedia":[{"type":"text/html","base64":false,"value":"<p>Kasa EC71 v4 and EC70 v4 firmware contains a static cryptographic private key stored in a read-only filesystem\nthat is shared across devices.&nbsp; An\nattacker with access to the firmware image can extract the embedded key.&nbsp; </p><p>\n\n</p><p>Successful\nexploitation may allow an unauthenticated attacker on the same network to use\nthis key in the web management service, compromising the confidentiality of\nencrypted communications. This may enable passive decryption of traffic or\nactive man-in-the-middle (MITM) attacks</p>"}]}],"references":[{"url":"https://www.tp-link.com/en/support/download/ec71/v4/#Firmware-Release-Notes","tags":["patch"]},{"url":"https://www.tp-link.com/us/support/download/ec71/v4/#Firmware-Release-Notes","tags":["patch"]},{"url":"https://www.tp-link.com/us/support/download/ec70/v4/#Firmware-Release-Notes","tags":["patch"]},{"url":"https://www.tp-link.com/en/support/download/ec70/v4/#Firmware-Release-Notes","tags":["patch"]},{"url":"https://www.tp-link.com/us/support/faq/5192/","tags":["vendor-advisory"]}],"metrics":[{"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}],"cvssV4_0":{"attackVector":"ADJACENT","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","subConfidentialityImpact":"NONE","vulnIntegrityImpact":"HIGH","subIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED","version":"4.0","baseSeverity":"HIGH","baseScore":8.6,"vectorString":"CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"}}],"credits":[{"lang":"en","value":"Christopher Childress","type":"finder"}],"source":{"discovery":"UNKNOWN"},"x_generator":{"engine":"Vulnogram 1.0.2"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-07-15T12:37:44.275721Z","id":"CVE-2026-9770","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-07-15T12:38:03.180Z"}}]}}