TP-Link has released firmware version 2.4.1 to remediate critical security vulnerabilities in Kasa Spot EC71 cameras, including unauthorized GPS exposure, insecure credential storage, and fleet-wide cryptographic key usage.
Key Points
- Firmware 2.4.1 addresses CVE-2026-9770 and CVE-2026-13230, which previously allowed unauthorized access to sensitive user data.
- The update eliminates the broadcast of precise GPS coordinates and hardware identifiers via unauthenticated UDP requests on port 9999.
- Security patches replace fleet-wide RSA keys with unique per-device certificates and implement at-rest encryption for stored user credentials.
- Previous firmware versions stored TP-Link ID passwords as unsalted MD5 hashes, creating risks for cross-domain account takeover across the TP-Link ecosystem.
- The vulnerabilities enabled a secondary market attack path where secondhand devices could leak a previous owner's home location and account credentials.