CVE-2026-13230

Published Jul 15, 2026

Last updated 5 days ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-13230 is an information disclosure vulnerability affecting TP-Link Kasa EC70 v4 and EC71 v4 smart cameras. This flaw resides within the local discovery mechanism of these devices, which inadvertently exposes sensitive geolocation information without requiring any authentication. An attacker situated on the same local network as the vulnerable camera can exploit this by sending specially crafted responses to retrieve geolocation-related data. The vulnerability primarily impacts the confidentiality of information, with no identified effects on the integrity or availability of the device. TP-Link has released firmware updates, specifically versions 2.4.0 Build 20260520 and 2.4.1 Build 20260621, to address this issue.

Description
An information disclosure vulnerability was identified in TP-Link Kasa EC70 v4 and EC71 v4 in the local discovery mechanism, which exposes sensitive geolocation information without requiring authentication. This issue allows an attacker on the same local network to retrieve geolocation-related data through crafted responses. The vulnerability impacts confidentiality only, with no evidence of integrity of availability impact.
Source
f23511db-6c3e-4e32-a477-6aa17d310630
NVD status
Awaiting Analysis

Risk scores

CVSS 4.0

Type
Secondary
Base score
5.3
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
MEDIUM

Weaknesses

f23511db-6c3e-4e32-a477-6aa17d310630
CWE-200

Social media

Hype score
Not currently trending