TP-Link Kasa EC70 and EC71 Information Disclosure Vulnerability

Vulnerability

A vulnerability allowing information disclosure has been identified in the TP-Link Kasa EC70 v4 and EC71 v4 models. This issue arises in the local discovery mechanism, which exposes sensitive geolocation data without requiring authentication. An attacker on the same local network can exploit this vulnerability by sending crafted responses to retrieve geolocation-related information. The vulnerability impacts confidentiality by exposing sensitive location data, with no known effects on integrity or availability.

Impact

Exploitation of this vulnerability allows for unauthorized access to sensitive geolocation information, which could be misused to track or monitor individuals' locations.

Remediation

Users are advised to update to the latest firmware version. The patched version for both the Kasa EC70 and EC71 is 2.4.0 Build 20260520 or 2.4.1 Build 20260621. Instructions for downloading the firmware are available on the TP-Link website.

Added: Jul 15, 2026, 3:28 AM
Updated: Jul 15, 2026, 3:28 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
4.7
remediation
7.7
relevance
9.6
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.