TP-Link Kasa EC70
cpe:2.3:h:tp-link:ec70:*:*:*:*:*:*:*, +1 more
- >= 4, < 4.6
A vulnerability allowing information disclosure has been identified in the TP-Link Kasa EC70 v4 and EC71 v4 models. This issue arises in the local discovery mechanism, which exposes sensitive geolocation data without requiring authentication. An attacker on the same local network can exploit this vulnerability by sending crafted responses to retrieve geolocation-related information. The vulnerability impacts confidentiality by exposing sensitive location data, with no known effects on integrity or availability.
Exploitation of this vulnerability allows for unauthorized access to sensitive geolocation information, which could be misused to track or monitor individuals' locations.
Users are advised to update to the latest firmware version. The patched version for both the Kasa EC70 and EC71 is 2.4.0 Build 20260520 or 2.4.1 Build 20260621. Instructions for downloading the firmware are available on the TP-Link website.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.