TP-Link Kasa Cameras Leaked Home GPS via Unauthenticated UDP for Six Years

A long-standing vulnerability in widely deployed home cameras exposed precise location data without authentication.

Abstract illustration of network broadcast waves and location data
AI-generated illustration · Sylvaris

The Vulnerability

Security researchers discovered that TP-Link's Kasa EC71 cameras transmitted home GPS coordinates through an unauthenticated UDP broadcast. The flaw persisted for approximately six years across multiple firmware versions.

Any device on the same network could intercept these broadcasts without credentials. The data included precise latitude and longitude coordinates configured during camera setup.

Attack Surface

The vulnerability required local network access, limiting remote exploitation. However, compromised devices or malicious software on home networks could harvest location data silently.

The exposure affects users who configured location services during initial setup. Many security cameras request GPS coordinates to enable features like geofencing or timezone automation.

Disclosure Timeline

The research was published through a public GitHub repository documenting IoT vulnerabilities. The documentation includes technical details of the UDP packet structure and proof-of-concept code.

TP-Link's response and patch status remain unclear from public sources. Users of affected Kasa EC71 models should check for firmware updates through the manufacturer's support channels.

sources
more in Security
Upbound breach enabled $13 million in fraudulent Acima leases Stolen customer data was directly weaponized to create fraudulent financial contracts, demonstrating how breach data enables immediate financial crime. Fake job interview delivers malware through Git hooks in take-home coding projects Attackers are weaponizing the technical interview process itself, embedding malicious Git hooks in legitimate-looking coding assignments to compromise developer workstations. South Korea National Diplomatic Academy breach exposes global diplomat data after ten-month intrusion A prolonged breach of diplomatic training infrastructure exposed sensitive personnel data of current and former foreign service officers worldwide, demonstrating the targeting of government educational systems.