Executive brief
TP-Link Kasa smart security cameras contain a security flaw where a secret digital key used to protect communications is identical across all devices of the same model. An attacker who extracts this key from the camera's software can intercept or spy on the video feeds and management traffic of other cameras on the same local network. This could lead to a significant loss of privacy and unauthorized access to the camera's management interface.
Technical details
A vulnerability exists in the firmware of TP-Link Kasa EC70 v4 and EC71 v4 cameras due to the use of a hard-coded cryptographic key (CWE-321). The static private key is stored within a read-only filesystem and is shared across all devices of these models. An attacker can extract this key from the publicly available firmware image. With the key, an unauthenticated attacker positioned on the same local network (adjacent) can decrypt encrypted traffic to the web management service or execute man-in-the-middle (MITM) attacks. The issue is addressed in firmware version 2.4.0 Build 20260520 rel.4191 and later.
Affected products
- TP-Link Kasa EC70 v4 Before 2.4.0 Build 20260520 rel.4191
- TP-Link Kasa EC71 v4 Before 2.4.0 Build 20260520 rel.4191
Timeline
- 2026-05-20: patched: Firmware build date for the fix
- 2026-07-14: advisory
- 2026-07-15: disclosed