Key Takeaways
- A researcher says TP-Link Kasa Spot EC71 cameras exposed precise GPS coordinates through an unauthenticated UDP request on port 9999.
- The report says the issue was present in firmware 2.3.26 and was remediated in firmware 2.4.1.
- The same disclosure also describes additional security issues, including fleet-wide RSA material and weak credential storage.
What happened
According to the supplied research note, Christopher Childress found that a Kasa Spot EC71 camera would answer a single unauthenticated UDP request with a full get_sysinfo response.
The response allegedly included precise GPS coordinates, device identifiers such as oemId, hwId, deviceId, and MAC-related values, plus the user-assigned device alias and firmware version string. The researcher says the data was protected only by a simple XOR scheme that could be decoded in packet tools.
The write-up says no authentication token, session credential, or prior setup step was needed to trigger the response. It also says GPS coordinates were stored from the mobile device used during account creation and persisted in firmware, rather than rotating over time.
The report places this behavior in a longer protocol history. It says the unauthenticated nature of TP-Link’s Smart Home Protocol on port 9999 had been documented publicly since 2016, and that similar GPS exposure had been reported for a Kasa camera in 2020. Based on that history, the author argues the EC71 issue was part of a broader pattern rather than an isolated bug.
The source also says TP-Link assigned CVE-2026-13230 to the GPS issue and that firmware 2.4.1 removed GPS coordinates from the get_sysinfo response. The same disclosure says other problems were also remediated in that release, including fleet-wide RSA certificate material and unsalted MD5 credential storage.
Why it matters
If accurate, this issue matters because location data is often more sensitive than basic device telemetry. A camera that returns precise home coordinates to any device on the local network creates a privacy risk even when the user is not actively using a geofencing feature.

The report is especially notable because it says the location data was not tied to a user-facing opt-in flow. The author argues that TP-Link’s own geofencing materials describe a different location model, while the firmware behavior collected and exposed coordinates independently of that feature.
There is also a lifecycle angle. The disclosure says the coordinates remained accessible on devices that were reset and later resold or transferred, which could create a secondary-market risk for former owners. The report claims that a buyer of a secondhand device could recover both old GPS data and account information from flash storage.
The source further says the GPS problem did not stand alone. It was described alongside other weaknesses, including a fleet-wide RSA key and unsalted MD5 password storage, which the researcher says could compound the impact if a device or account were compromised.
What to watch
The main thing to watch is how broadly TP-Link applied the fix. The source says 2.4.1 removed the GPS exposure path, but it also suggests that the underlying protocol had been vulnerable for years and had appeared in multiple Kasa products.
It is also worth watching whether the remediation is limited to this model or extends across the product line. The researcher cites earlier public work on other TP-Link devices and argues that similar code may have been shared across generations.
Finally, this case is a reminder that IoT privacy flaws can outlast the original feature that makes them easier to overlook. Even if a user never turns on geofencing, the report says the camera could still store and disclose precise location data. That makes firmware-level review, not just app-level feature consent, central to the security discussion.



