TP-Link Kasa EC71 Cameras Exposed Home GPS Data via Unauthenticated UDP for Six Years

Security researchers uncovered a long‑standing vulnerability in TP‑Link Kasa EC71 smart cameras. The flaw allowed anyone to send unauthenticated UDP packets to the device. In response, the camera

Security researchers uncovered a long‑standing vulnerability in TP‑Link Kasa EC71 smart cameras. The flaw allowed anyone to send unauthenticated UDP packets to the device. In response, the camera broadcast the homeowner’s GPS coordinates. The issue persisted for approximately six years before disclosure. The vulnerability was documented in a publicly available research repository. TP‑Link has been notified and is expected to issue a firmware update. Users with affected devices are advised to monitor network traffic for unexpected UDP queries. The discovery highlights broader risks in IoT devices that expose location data. Analysts suggest that similar GPS‑leaking bugs may exist in other consumer cameras. Ongoing scrutiny of IoT firmware is recommended to prevent future exposures.