CVE-2026-9770
Kasa EC71 v4 and EC70 v4 firmware contains a static cryptographic private key stored in a read-only filesystem that is shared across devices. An attacker with access to the firmware image can extract the embedded key.
Successful exploitation may allow an unauthenticated attacker on the same network to use this key in the web management service, compromising the confidentiality of encrypted communications. This may enable passive decryption of traffic or active man-in-the-middle (MITM) attacks
CVSS
- Versión: 4.0
- Vector: CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Puntuación base: 8.6
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.31%
- Percentil entre todas las CVEs puntuadas: 22
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1210Exploitation of Remote Serviceslateral movement75 % - Impacto principal
T1557Adversary-in-the-Middlecredential access · collection85 % - Impacto secundario
T1040Network Sniffingcredential access · discovery80 %
Clave criptográfica estática extraída del firmware permite MITM y pasiva decryption en servicios web de dispositivos en red adyacente (AV:A, sin autenticación, CWE-321).
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (2)
CWE
- CWE-321
Referencias
- https://www.tp-link.com/en/support/download/ec70/v4/#Firmware-Release-Notes
- https://www.tp-link.com/en/support/download/ec71/v4/#Firmware-Release-Notes
- https://www.tp-link.com/us/support/download/ec70/v4/#Firmware-Release-Notes
- https://www.tp-link.com/us/support/download/ec71/v4/#Firmware-Release-Notes
- https://www.tp-link.com/us/support/faq/5192/
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-9770",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-9770",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2026-07-15T12:37:44.275721Z"
}
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.3,
"attackVector": "ADJACENT_NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 1.6
}
],
"cvssMetricV40": [
{
"type": "Secondary",
"source": "f23511db-6c3e-4e32-a477-6aa17d310630",
"cvssData": {
"Safety": "NOT_DEFINED",
"version": "4.0",
"Recovery": "NOT_DEFINED",
"baseScore": 8.6,
"Automatable": "NOT_DEFINED",
"attackVector": "ADJACENT",
"baseSeverity": "HIGH",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"exploitMaturity": "NOT_DEFINED",
"providerUrgency": "NOT_DEFINED",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"privilegesRequired": "NONE",
"subIntegrityImpact": "NONE",
"vulnIntegrityImpact": "HIGH",
"integrityRequirement": "NOT_DEFINED",
"modifiedAttackVector": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"vulnAvailabilityImpact": "NONE",
"availabilityRequirement": "NOT_DEFINED",
"modifiedUserInteraction": "NOT_DEFINED",
"modifiedAttackComplexity": "NOT_DEFINED",
"subConfidentialityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"confidentialityRequirement": "NOT_DEFINED",
"modifiedAttackRequirements": "NOT_DEFINED",
"modifiedPrivilegesRequired": "NOT_DEFINED",
"modifiedSubIntegrityImpact": "NOT_DEFINED",
"modifiedVulnIntegrityImpact": "NOT_DEFINED",
"vulnerabilityResponseEffort": "NOT_DEFINED",
"modifiedSubAvailabilityImpact": "NOT_DEFINED",
"modifiedVulnAvailabilityImpact": "NOT_DEFINED",
"modifiedSubConfidentialityImpact": "NOT_DEFINED",
"modifiedVulnConfidentialityImpact": "NOT_DEFINED"
}
}
]
},
"affected": [
{
"source": "f23511db-6c3e-4e32-a477-6aa17d310630",
"affectedData": [
{
"vendor": "TP-Link Systems Inc.",
"product": "Kasa EC71 v4",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "2.4.0 Build 20260520 rel.4191",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "TP-Link Systems Inc.",
"product": "Kasa EC70 v4",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "2.4.0 Build 20260520 rel.4191",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2026-07-15T01:17:10.387",
"references": [
{
"url": "https://www.tp-link.com/en/support/download/ec70/v4/#Firmware-Release-Notes",
"tags": [
"Release Notes"
],
"source": "f23511db-6c3e-4e32-a477-6aa17d310630"
},
{
"url": "https://www.tp-link.com/en/support/download/ec71/v4/#Firmware-Release-Notes",
"tags": [
"Release Notes"
],
"source": "f23511db-6c3e-4e32-a477-6aa17d310630"
},
{
"url": "https://www.tp-link.com/us/support/download/ec70/v4/#Firmware-Release-Notes",
"tags": [
"Release Notes"
],
"source": "f23511db-6c3e-4e32-a477-6aa17d310630"
},
{
"url": "https://www.tp-link.com/us/support/download/ec71/v4/#Firmware-Release-Notes",
"tags": [
"Release Notes"
],
"source": "f23511db-6c3e-4e32-a477-6aa17d310630"
},
{
"url": "https://www.tp-link.com/us/support/faq/5192/",
"tags": [
"Vendor Advisory"
],
"source": "f23511db-6c3e-4e32-a477-6aa17d310630"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "f23511db-6c3e-4e32-a477-6aa17d310630",
"description": [
{
"lang": "en",
"value": "CWE-321"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Kasa EC71 v4 and EC70 v4 firmware contains a static cryptographic private key stored in a read-only filesystem\nthat is shared across devices. An\nattacker with access to the firmware image can extract the embedded key. \n\n\n\n\n\n\n\n\n\nSuccessful\nexploitation may allow an unauthenticated attacker on the same network to use\nthis key in the web management service, compromising the confidentiality of\nencrypted communications. This may enable passive decryption of traffic or\nactive man-in-the-middle (MITM) attacks"
}
],
"lastModified": "2026-08-06T18:20:49.317",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:tp-link:kasa_ec71_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B8EDB211-D7D4-48D2-ACA0-25733AED4344",
"versionEndExcluding": "2.4.0"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:tp-link:kasa_ec71:4.0:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "388D1C66-65E2-4214-B98E-3BAA652E7C72"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:tp-link:kasa_ec70_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3AE4B727-5E1A-42AE-954B-6E8E4AB15B05",
"versionEndExcluding": "2.4.0"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:tp-link:kasa_ec70:4.0:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "D443B952-0963-4083-9B4B-6D587AAC8B67"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "f23511db-6c3e-4e32-a477-6aa17d310630"
}