AI description
CVE-2026-13230 is an information disclosure vulnerability affecting TP-Link Kasa EC70 v4 and EC71 v4 smart cameras. This flaw resides within the local discovery mechanism of these devices, which inadvertently exposes sensitive geolocation information without requiring any authentication. An attacker situated on the same local network as the vulnerable camera can exploit this by sending specially crafted responses to retrieve geolocation-related data. The vulnerability primarily impacts the confidentiality of information, with no identified effects on the integrity or availability of the device. TP-Link has released firmware updates, specifically versions 2.4.0 Build 20260520 and 2.4.1 Build 20260621, to address this issue.
- Description
- An information disclosure vulnerability was identified in TP-Link Kasa EC70 v4 and EC71 v4 in the local discovery mechanism, which exposes sensitive geolocation information without requiring authentication. This issue allows an attacker on the same local network to retrieve geolocation-related data through crafted responses. The vulnerability impacts confidentiality only, with no evidence of integrity of availability impact.
- Source
- f23511db-6c3e-4e32-a477-6aa17d310630
- NVD status
- Awaiting Analysis
CVSS 4.0
- Type
- Secondary
- Base score
- 5.3
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity
- MEDIUM
- f23511db-6c3e-4e32-a477-6aa17d310630
- CWE-200
- Hype score
- Not currently trending
Vulnerabilidad en cámaras TP-Link permite ataques MitM TP-Link ha lanzado actualizaciones de seguridad para corregir dos vulnerabilidades en sus cámaras inteligentes Kasa EC70 v4 y EC71 v4 CVE-2026-9770 y CVE-2026-13230 https://t.co/ppGcxfyswi
@elhackernet
17 Jul 2026
3446 Impressions
15 Retweets
36 Likes
9 Bookmarks
0 Replies
0 Quotes
🚨 TP-Link Kasa EC70/EC71 v4 cameras are affected by CVE-2026-9770 & CVE-2026-13230. A hardcoded encryption key could enable MitM attacks with local network access. 🔗 https://t.co/41YsAiRUSM #CyberSecurity #IoTSecurity #CVE https://t.co/9zTMpVuyIi
@Xpert4Cyber
17 Jul 2026
3 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨*CVE* CVE-2026-13230 An information disclosure vulnerability was identified in TP-Link Kasa EC70 v4 and EC71 v4 in the local discovery mechanism, which exposes sensitive geolocation infor… https://t.co/KjwBapKRAG ----- Traducción: CVE-2026-13230 Se … https://t.co/utmtN
@infoflowcloud
15 Jul 2026
30 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes