Do you use a webcam in the bedroom? Urgently update the firmware until Wi-Fi neighbors intercept access to the broadcast

Depov

Moderator
Staff member
MODERATOR
ULTIMATE
SUPREME
PREMIUM
MEMBER
Joined
Feb 18, 2025
Messages
345
Reaction score
502
Deposit
0$
Home cameras rarely leave the LAN, but vulnerabilities in the TP-Link Kasa EC70 and EC71 allow the attacker inside it to intercept administrator accounts and receive information about the location of the device.

The most dangerous vulnerability CVE-2026-9770 received a score of 8.6 points on the CVSS 4.0 scale. In the firmware of the cameras is a rigidly prescribed cryptographic key. The attacker can retrieve the key, decrypt the data exchange between the camera and the web control interface, and then conduct an attack “man in the middle” and intercept administrative data. For exploitation, no rights in the system or the actions of the owner are required, but the attacker must be in the same local network.

Second vulnerability CVE-2026-13230 with a score of 5.3 points on the CVSS 4.0 scale, discloss geolocation information through the local device detection mechanism. A specially formed request allows you to obtain location-related metadata without authorization. The error does not make it possible to change the operation of the camera or disable the device, but can help to make a map of the placement of cameras and collect information about the owners.

The problems affect the Kasa EC70 v4 with flashes earlier than 2.4.0 Build Build 20260520 rel.4191, and EC71 v4 with versions up to 2.4.1 Build 20260621 rel. 76536. TP-Link has already released corrected firmware and also recommends updating the Kasa mobile app.

The whole risk is limited by the local network, but access to it may appear through any other compromised IoT device or weak Wi-Fi protection. Camera owners are advised to install fresh firmware, take out IoT devices in a separate network segment, strengthen the protection of wireless connection and track unusual traffic.
 
Top Bottom