CVE-2026-9770

Published Jul 15, 2026

Last updated 5 days ago

CVSS high 8.6
Kasa EC71
Kasa EC70

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-9770 describes a vulnerability found in the firmware of Kasa EC71 v4 and EC70 v4 devices. The affected firmware contains a static cryptographic private key that is stored in a read-only filesystem and is shared across all devices. An attacker who gains access to the firmware image can extract this embedded key. This extracted key can then be utilized by an unauthenticated attacker on the same network to compromise the confidentiality of encrypted communications with the web management service. This could potentially lead to passive decryption of traffic or active man-in-the-middle (MITM) attacks.

Description
Kasa EC71 v4 and EC70 v4 firmware contains a static cryptographic private key stored in a read-only filesystem that is shared across devices.  An attacker with access to the firmware image can extract the embedded key.  Successful exploitation may allow an unauthenticated attacker on the same network to use this key in the web management service, compromising the confidentiality of encrypted communications. This may enable passive decryption of traffic or active man-in-the-middle (MITM) attacks
Source
f23511db-6c3e-4e32-a477-6aa17d310630
NVD status
Awaiting Analysis

Risk scores

CVSS 4.0

Type
Secondary
Base score
8.6
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
HIGH

Weaknesses

f23511db-6c3e-4e32-a477-6aa17d310630
CWE-321

Social media

Hype score
Not currently trending