Junglewise Threat Intelligence

CVE-2026-13230: TP-Link Kasa EC70 and EC71 information disclosure in local discovery

CVE-2026-13230 · Severity: info · CVSS 5.3 · Published 2026-07-15

Vendors: TP-Link.

Executive brief

TP-Link Kasa smart cameras are used for home security and monitoring. A security flaw in the local discovery feature allows anyone on the same Wi-Fi network to see the camera's precise physical location without needing a password. This could allow an unauthorized person to track the device's location, though it does not allow them to view video feeds or control the camera.

Technical details

An information disclosure vulnerability (CWE-200) exists in the local discovery mechanism of TP-Link Kasa EC70 v4 and EC71 v4 smart cameras. The flaw allows an unauthenticated attacker located on the same local network (adjacent) to retrieve sensitive geolocation-related data by sending crafted responses to the discovery service. The vulnerability only impacts confidentiality, with no reported impact on device integrity or availability. A fix is available in firmware version 2.4.1 Build 20260621 rel.76536 and later.

Affected products

  • TP-Link Kasa EC70 v4 Before 2.4.1 Build 20260621 rel.76536
  • TP-Link Kasa EC71 v4 Before 2.4.1 Build 20260621 rel.76536

Timeline

  • 2026-06-21: patched: Firmware version 2.4.1 Build 20260621 released to address the issue.
  • 2026-07-15: advisory: CVE published to the NVD.

References

Related threats