TP-Link Kasa Camera Leaks Home GPS via Unauthenticated Port
20 Jul 2026
What happened
Researchers have published details of a long-standing vulnerability in TP-Link's Kasa Spot EC71 smart camera that allowed anyone on the same local network to retrieve a device's precise home GPS coordinates—without any authentication. The flaw lives in an unauthenticated UDP service on port 9999, and the underlying protocol weakness has reportedly been publicly known since July 2016, with GPS exposure specifically across TP-Link's camera line documented since August 2020. TP-Link fixed an identical vulnerability class in its smart plugs back in November 2020, but the camera issue persisted for years afterward.
The vulnerable firmware (version 2.3.26) was built on April 25, 2024. The vendor was contacted under Coordinated Vulnerability Disclosure protocols on January 5, 2026, and the research was made public on July 16, 2026. A fix is available in firmware 2.4.1, though no specific release date for that patch is provided in the disclosure.
Why this one is different
Unlike a typical one-off bug, researchers say this disclosure surfaces several compounding weaknesses:
- Static GPS leakage: The coordinates returned by the device do not rotate, meaning a single capture provides a persistent, unchanging record of the owner's home location.
- Fleet-wide cryptographic exposure: TP-Link reportedly uses a shared 2048-bit RSA key/certificate pair (issued 2021, valid until July 2031) across its device fleet, alongside a legacy 1024-bit pair (issued 2014, expired July 2024). Extracting the active private key from a single EC71 unit is said to yield material valid across the entire deployed fleet—meaning one compromised device could theoretically implicate many others.
- Weak credential storage: User credentials are reportedly stored as unsalted MD5 hashes, a hashing scheme researchers say is crackable with modern rainbow tables, potentially enabling account takeover across multiple TP-Link products.
- Secondary-market risk: Resold or factory-reset devices may still expose a previous owner's credentials and GPS data, according to the disclosure.
Notably, Kasa's own geofencing feature—which relies on location data—launched in September 2023, meaning the location-tracking capability tied to this hardware was actively promoted to users years before the exposure was publicly detailed.
Where vendor and researcher disagree
Sources differ on severity. TP-Link rates the GPS vulnerability at CVSS 4.0 score 8.6, while the researcher scores it lower at 7.1. The credential storage issue received a vendor CVSS 4.0 score of 5.3. The report does not clarify why the scores diverge, but the gap illustrates a broader pattern: vendor and independent severity assessments for the same flaw can differ meaningfully.
What's still unclear
Several details remain unspecified in the disclosure: the exact patch release date for firmware 2.4.1, the number of affected devices or households, whether other Kasa camera models beyond the EC71 share the same vulnerable code, and whether any CVE identifier or official TP-Link security advisory has been issued. It's also not confirmed whether TP-Link has publicly acknowledged the January 2026 disclosure, what precision the leaked GPS coordinates carry, or whether real-world exploitation has occurred outside of research testing.
Why founders should care
For founders building or shipping connected hardware, this case is a useful cautionary template rather than an isolated incident:
- Legacy flaws can linger for years. The gap between the 2016 protocol disclosure and this 2026 publication suggests that known vulnerability classes may likely persist unaddressed across product lines far longer than teams assume—especially when a fix is applied to one product category (smart plugs, 2020) but not adjacent ones (cameras).
- Shared cryptographic material raises breach blast radius. If a startup issues one key or certificate across an entire device fleet rather than per-unit credentials, a single compromised unit could plausibly expose cryptographic material for the whole fleet—a design choice worth auditing early.
- Legacy hashing practices are a quiet liability. Unsalted MD5 storage is a well-known weak practice; teams should treat this as a prompt to review their own authentication stacks, since such gaps may not surface until external researchers find them.
- Resale and factory-reset flows deserve explicit security design. If devices can retain previous owners' credentials or location data after a reset, secondary-market resale could become an unplanned attack surface—something hardware-focused founders should test for directly rather than assume is handled.
- Vendor severity scores shouldn't be taken at face value. With vendor and researcher CVSS ratings diverging here (8.6 vs. 7.1), founders relying solely on vendor-supplied severity data for third-party components may be underestimating real-world risk in their own risk assessments.
The opportunity angle
The disclosure also points to potential market openings: startups that implement per-device cryptographic keys instead of shared fleet-wide keys, offer third-party security auditing for consumer IoT products, or specialize in secure credential hashing practices could position themselves as more trustworthy alternatives in a market where legacy vulnerabilities apparently persist for years. Structured disclosure processes like the one used here may also serve as a workable model for startups still building out their own vulnerability disclosure policies.