TP-Link Kasa cameras leaked home GPS via unauthenticated UDP for 6 years
Security researchers have disclosed multiple vulnerabilities in TP-Link Kasa Spot EC71 cameras, including unauthenticated GPS data exposure that persisted for years. The vendor has released a firmware patch to address these issues, which also included insecure credential storage and cryptographic failures.
Why it matters
This highlights critical privacy and security risks in consumer IoT devices, emphasizing the need for better coordinated disclosure and firmware maintenance.
Author: Christopher Childress (BadChemical) Status: Patched, CVE-2026-9770 (RSA/IAM) and CVE-2026-13230 (GPS) remediated in 2.4.1.
Vendor: TP-Link Systems Inc. / Kasa Product: Kasa Spot EC71 Firmware Version: 2.3.26 (Build Date: 20240425, Release ID: 33797) Patched Firmware: 2.4.1 CVE: CVE-2026-9770 / CVE-2026-13230 Published: July 16th, 2026
This repository contains proof of concept for patched vulnerabilities in TP-Link Kasa Spot EC71 indoor cameras. This information is published strictly for educational purposes and defensive research. The vendor was contacted in accordance with standard Coordinated Vulnerability Disclosure protocols on January 5, 2026. All three primary findings, fleet-wide RSA key, unsalted MD5 credential storage, and unauthenticated GPS exposure, have been remediated in v2.4.1. All device-specific identifiers, credential hashes, and global private keys have been heavily redacted to prevent abuse.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in