AUTO-UPDATED

TP-Link Kasa cameras leaked home GPS via unauthenticated UDP for 6 years

TP-Link has released firmware version 2.4.1 to remediate critical security vulnerabilities in Kasa Spot EC71 cameras, including unauthorized GPS exposure, insecure credential storage, and fleet-wide cryptographic key usage.

Key Points

  • Firmware 2.4.1 addresses CVE-2026-9770 and CVE-2026-13230, which previously allowed unauthorized access to sensitive user data.
  • The update eliminates the broadcast of precise GPS coordinates and hardware identifiers via unauthenticated UDP requests on port 9999.
  • Security patches replace fleet-wide RSA keys with unique per-device certificates and implement at-rest encryption for stored user credentials.
  • Previous firmware versions stored TP-Link ID passwords as unsalted MD5 hashes, creating risks for cross-domain account takeover across the TP-Link ecosystem.
  • The vulnerabilities enabled a secondary market attack path where secondhand devices could leak a previous owner's home location and account credentials.

Why it Matters

These vulnerabilities highlight significant privacy risks for smart home users, as they allowed attackers to correlate physical home locations with compromised cloud account credentials. The remediation is essential for protecting users against unauthorized access to their broader network infrastructure and personal surveillance data.
Github.com Published by BadChemical
Read original