TP-Link Patches Kasa Camera Flaws That Exposed Admin Credentials and Home Location Data

TP-Link has patched two vulnerabilities in its Kasa EC70 v4 and EC71 v4 smart cameras that let an attacker already on the same local network intercept administrator login credentials and pull sensitive location data from the device without ever logging in.

The more serious flaw, CVE-2026-9770, carries a CVSS score of 8.6 and traces back to a cryptographic private key hardcoded into the camera's firmware rather than generated uniquely per device. Because every unpatched EC70 v4 and EC71 v4 shares the same key, an attacker on the local network can use it to decrypt traffic between the camera and its web management interface, position themselves in a man-in-the-middle attack, and harvest admin credentials — all without needing any privileges or user interaction to begin with.

The second flaw, CVE-2026-13230, sits in the camera's local discovery feature — the mechanism normally used to help the Kasa app find and pair with the device during setup. That feature responds to discovery requests without requiring authentication, so an attacker on the same network can send a crafted request and get geolocation data tied to the camera back, no credentials needed. TP-Link rated it Medium severity, but independent researchers who examined the flaw in detail argue that severity score understates the real-world risk: precise coordinates can pinpoint a residential address closely enough to cross-reference against public property records, exposing far more than the vendor's rating suggests.

Both issues were addressed in firmware version 2.4.1, and TP-Link is urging EC70 v4 and EC71 v4 owners to update through the Kasa app immediately, along with updating the app itself for compatibility. Unlike the still-unpatched Shark vacuum flaw we reported on this week, this one has a fix available today — the risk from here on belongs to whichever owners never update their firmware.

It's a pattern we've tracked closely: a device built to watch the home ends up exposing the people inside it instead — something we broke down at length in our feature on why smart TVs, cameras and other connected devices keep becoming hackers' easiest targets.