CVE-2026-13230
Awaiting Analysis Awaiting Analysis - Queue

Information Disclosure in TP-Link Kasa EC70 EC71

Vulnerability report for CVE-2026-13230, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-15

Last updated on: 2026-07-15

Assigner: TPLink

Description

An information disclosure vulnerability was identified in TP-Link Kasa EC70 v4 and EC71 v4 in the local discovery mechanism, which exposes sensitive geolocation information without requiring authentication. This issue allows an attacker on the same local network to retrieve geolocation-related data through crafted responses. The vulnerability impacts confidentiality only, with no evidence of integrity of availability impact.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-15
Last Modified
2026-07-15
Generated
2026-08-04
AI Q&A
2026-07-15
EPSS Evaluated
2026-08-02
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
tp-link kasa_ec70 4
tp-link kasa_ec71 4

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-200 The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an information disclosure issue in TP-Link Kasa EC70 v4 and EC71 v4 cameras. It allows an attacker on the same local network to retrieve sensitive geolocation data without authentication by exploiting the local discovery mechanism.

Detection Guidance

This vulnerability involves an information disclosure issue in TP-Link Kasa EC70 v4 and EC71 v4 devices. To detect it, monitor network traffic for unauthorized geolocation data requests or responses from these devices. Use packet capture tools like Wireshark to inspect local network communication involving the devices. Look for crafted responses exposing sensitive geolocation information without authentication.

Impact Analysis

An attacker could access your geolocation information, compromising your privacy. This could reveal where you live or other sensitive locations tied to the device.

Compliance Impact

This vulnerability may violate privacy regulations like GDPR or HIPAA by exposing personal geolocation data without consent. Organizations must address it to maintain compliance.

Mitigation Strategies

Immediately update the firmware of affected TP-Link Kasa EC70 v4 and EC71 v4 devices to the latest version provided by TP-Link. Isolate the devices from untrusted networks if possible. Disable unnecessary local discovery features if supported by firmware updates. Monitor for unusual network activity involving these devices.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-13230. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart