PT-2026-58867 · Tp Link · Kasa Ec71 V4+1
CVSS v4.0
8.6
High
| Vector | AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Kasa EC71 v4
Kasa EC70 v4
Description
The firmware contains a static cryptographic private key stored in a read-only filesystem that is shared across devices. An attacker with access to the firmware image can extract this embedded key. Successful exploitation may allow an unauthenticated attacker on the same network to use the key within the web management service, compromising the confidentiality of encrypted communications. This can lead to the theft of admin credentials through passive decryption of traffic or active man-in-the-middle (MITM) attacks, where an attacker intercepts and potentially alters communication between two parties.
Recommendations
Update the firmware for Kasa EC71 v4.
Update the firmware for Kasa EC70 v4.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kasa Ec70 V4
Kasa Ec71 V4