• Sources: CVE-2026-9770 (NVD), CVE-2026-13230 (NVD)
  • Summary: Two flaws in TP-Link Kasa EC70 and EC71 version 4 cameras were disclosed this week. CVE-2026-9770 (CVSS 8.6) is a hardcoded cryptographic key in firmware that lets a local-network attacker decrypt traffic between the camera and its web management interface. CVE-2026-13230 (CVSS 5.3) exposes GPS coordinates through the unauthenticated local discovery UDP response, so a crafted discovery request returns location metadata without authentication. TP-Link released fixed firmware (2.4.0 Build 20260520 and later, with coordinates removed in 2.4.1) and urges upgrades. Exploitation requires access to the same local network.
  • Why it matters: A hardcoded key combined with unauthenticated location disclosure gives an attacker already on the LAN a direct path to camera compromise and physical-location data.

send feedback on this story