Static Cryptographic Key Vulnerability in Kasa Smart Devices
CVE-2026-9770

8.6HIGH

What is CVE-2026-9770?

CVE-2026-9770 is a vulnerability affecting Kasa Smart Devices, specifically identified in the firmware versions EC71 v4 and EC70 v4 provided by Tp-link Systems Inc. This vulnerability stems from the presence of a static cryptographic private key that is improperly stored in a read-only filesystem, which is a significant security flaw. The static nature of the key means that it is shared across multiple devices, creating a critical point of weakness. If an attacker gains access to the firmware image, they can extract the private key, potentially compromising the security mechanisms of the devices.

The implications of this vulnerability are severe for organizations relying on Kasa Smart Devices. An unauthenticated attacker on the same network can leverage the extracted key to interact with the web management service, which could result in severe breaches of the confidentiality of encrypted communications. This vulnerability not only exposes sensitive information but could also lead to broader network infiltration and exploitation of connected devices.

Potential impact of CVE-2026-9770

  1. Passive Traffic Decryption: The extraction of the static cryptographic key allows attackers to decrypt sensitive information transmitted over the network, leading to the potential exposure of confidential data.

  2. Man-in-the-Middle (MITM) Attacks: Attackers could utilize the compromised key to perform MITM attacks, intercepting and altering communications between devices without detection. This can allow for the manipulation of data and commands sent through the network.

  3. Compromise of Network Security: By exploiting this vulnerability, attackers can gain unauthorized access to networked Kasa Smart Devices. This could facilitate further attacks within the network, posing a significant risk to the integrity and security of the entire system.

Affected Version(s)

Kasa EC70 v4 0 < 2.4.0 Build 20260520 rel.4191

Kasa EC71 v4 0 < 2.4.0 Build 20260520 rel.4191

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Christopher Childress
.