TP-Link Kasa cameras leaked home GPS via unauthenticated UDP for 6 years
Security researchers have disclosed multiple vulnerabilities in TP-Link Kasa Spot EC71 cameras, including unauthenticated GPS data exposure that persisted for years. The vendor has released a firmware patch to address these issues, which also included insecure credential storage and cryptographic failures.
Why it matters
This highlights critical privacy and security risks in consumer IoT devices, emphasizing the need for better coordinated disclosure and firmware maintenance.
Author: Christopher Childress (BadChemical) Status: Patched, CVE-2026-9770 (RSA/IAM) and CVE-2026-13230 (GPS) remediated in 2.4.1.
Technical disclosure based on security research and vendor remediation.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in