TP-Link Kasa EC71 Cameras Exposed Home GPS Data via Unauthenticated UDP for Six Years
Security researchers uncovered a long‑standing vulnerability in TP‑Link Kasa EC71 smart cameras. The flaw allowed anyone to send unauthenticated UDP packets to the device. In response, the camera
Security researchers uncovered a long‑standing vulnerability in TP‑Link Kasa EC71 smart cameras. The
flaw allowed anyone to send unauthenticated UDP packets to the device. In response, the camera
broadcast the homeowner’s GPS coordinates. The issue persisted for approximately six years before
disclosure. The vulnerability was documented in a publicly available research repository. TP‑Link
has been notified and is expected to issue a firmware update. Users with affected devices are
advised to monitor network traffic for unexpected UDP queries. The discovery highlights broader
risks in IoT devices that expose location data. Analysts suggest that similar GPS‑leaking bugs may
exist in other consumer cameras. Ongoing scrutiny of IoT firmware is recommended to prevent future
exposures.