Tech Current

Research says TP-Link Kasa cameras exposed home GPS over unauthenticated UDP for years

A security write-up on the Kasa Spot EC71 says a single UDP request could return precise GPS coordinates and device details without authentication, and that TP-Link has since patched the issue in firmware 2.4.1.

Published by Tech Current · Publisher Alex Naz
Research says TP-Link Kasa cameras exposed home GPS over unauthenticated UDP for years
AI-assisted editorial illustration for this article.

Key Takeaways

  • A researcher says TP-Link Kasa Spot EC71 cameras exposed precise GPS coordinates through an unauthenticated UDP request on port 9999.
  • The report says the issue was present in firmware 2.3.26 and was remediated in firmware 2.4.1.
  • The same disclosure also describes additional security issues, including fleet-wide RSA material and weak credential storage.

What happened

According to the supplied research note, Christopher Childress found that a Kasa Spot EC71 camera would answer a single unauthenticated UDP request with a full get_sysinfo response.

The response allegedly included precise GPS coordinates, device identifiers such as oemId, hwId, deviceId, and MAC-related values, plus the user-assigned device alias and firmware version string. The researcher says the data was protected only by a simple XOR scheme that could be decoded in packet tools.

The write-up says no authentication token, session credential, or prior setup step was needed to trigger the response. It also says GPS coordinates were stored from the mobile device used during account creation and persisted in firmware, rather than rotating over time.

The report places this behavior in a longer protocol history. It says the unauthenticated nature of TP-Link’s Smart Home Protocol on port 9999 had been documented publicly since 2016, and that similar GPS exposure had been reported for a Kasa camera in 2020. Based on that history, the author argues the EC71 issue was part of a broader pattern rather than an isolated bug.

The source also says TP-Link assigned CVE-2026-13230 to the GPS issue and that firmware 2.4.1 removed GPS coordinates from the get_sysinfo response. The same disclosure says other problems were also remediated in that release, including fleet-wide RSA certificate material and unsalted MD5 credential storage.

Why it matters

If accurate, this issue matters because location data is often more sensitive than basic device telemetry. A camera that returns precise home coordinates to any device on the local network creates a privacy risk even when the user is not actively using a geofencing feature.

Illustration for Research says TP-Link Kasa cameras exposed home GPS over unauthenticated UDP for years
AI-assisted editorial illustration for this article.

The report is especially notable because it says the location data was not tied to a user-facing opt-in flow. The author argues that TP-Link’s own geofencing materials describe a different location model, while the firmware behavior collected and exposed coordinates independently of that feature.

There is also a lifecycle angle. The disclosure says the coordinates remained accessible on devices that were reset and later resold or transferred, which could create a secondary-market risk for former owners. The report claims that a buyer of a secondhand device could recover both old GPS data and account information from flash storage.

The source further says the GPS problem did not stand alone. It was described alongside other weaknesses, including a fleet-wide RSA key and unsalted MD5 password storage, which the researcher says could compound the impact if a device or account were compromised.

What to watch

The main thing to watch is how broadly TP-Link applied the fix. The source says 2.4.1 removed the GPS exposure path, but it also suggests that the underlying protocol had been vulnerable for years and had appeared in multiple Kasa products.

It is also worth watching whether the remediation is limited to this model or extends across the product line. The researcher cites earlier public work on other TP-Link devices and argues that similar code may have been shared across generations.

Finally, this case is a reminder that IoT privacy flaws can outlast the original feature that makes them easier to overlook. Even if a user never turns on geofencing, the report says the camera could still store and disclose precise location data. That makes firmware-level review, not just app-level feature consent, central to the security discussion.

Watch next

How One Presentation Frames Surveillance Capitalism as a Design Problem — and a Civic One

How One Presentation Frames Surveillance Capitalism as a Design Problem — and a Civic One

A community talk argues that data-hungry platforms do more than track people: they shape behavior, concentrate power, and make privacy harder to defend without public pressure.

ClickFix Is No Longer Just a Low-End Scam — Even Elite Hackers Are Using It

ClickFix Is No Longer Just a Low-End Scam — Even Elite Hackers Are Using It

A social-engineering trick once associated with lower-end crime is being adopted by more sophisticated threat actors, broadening its importance for defenders.

What Trump’s newly declassified election documents do — and don’t — show about US voting risks

What Trump’s newly declassified election documents do — and don’t — show about US voting risks

Trump is using a fresh trove of declassified material to argue that American elections remain vulnerable, but the documents described in the source context mostly revisit long-known concerns rather than proving past election outcomes were altered.

Sources

Analytics, advertising, and privacy choices

We use analytics and advertising cookies only with your permission. You can change this choice later from the footer.

Privacy policy