TP-Link Kasa Cameras Leaked Home GPS via Unauthenticated UDP for Six Years
A long-standing vulnerability in widely deployed home cameras exposed precise location data without authentication.
The Vulnerability
Security researchers discovered that TP-Link's Kasa EC71 cameras transmitted home GPS coordinates through an unauthenticated UDP broadcast. The flaw persisted for approximately six years across multiple firmware versions.
Any device on the same network could intercept these broadcasts without credentials. The data included precise latitude and longitude coordinates configured during camera setup.
Attack Surface
The vulnerability required local network access, limiting remote exploitation. However, compromised devices or malicious software on home networks could harvest location data silently.
The exposure affects users who configured location services during initial setup. Many security cameras request GPS coordinates to enable features like geofencing or timezone automation.
Disclosure Timeline
The research was published through a public GitHub repository documenting IoT vulnerabilities. The documentation includes technical details of the UDP packet structure and proof-of-concept code.
TP-Link's response and patch status remain unclear from public sources. Users of affected Kasa EC71 models should check for firmware updates through the manufacturer's support channels.