TP-Link Kasa Cameras Leaked Home GPS via Unauthenticated UDP for Six Years
TP-Link Kasa cameras leaked home GPS via unauthenticated UDP for 6 years
I discovered that TP-Link Kasa Spot EC71 cameras exposed precise home GPS coordinates and user credentials through unauthenticated UDP packets for six years. My analysis also revealed fleet-wide hardcoded RSA keys and unsalted MD5 password storage, enabling cross-domain account takeovers. After a challenging disclosure process involving a bricked test device, TP-Link patched these critical flaws in firmware 2.4.1.
This advisory documents a pattern of targeted, incremental remediation rather than a comprehensive architectural security review.
- drnick1
This underscores the principle that IoT devices should not be allowed to communicate over the public Internet. Pretty much all cheap, Chinese-made hardware of this kind has intentional or unintentional security holes waiting to be exploited.
- gruez
The report seems obviously AI generated, so I can't be bothered to read in its entirety, but based on my quick skim, "leaked home GPS" makes it sound worse than it is. Unless you're dumb enough to set DMZ on this device, this won't be exposed to the internet, and if it's LAN only, don't you already know the location? Even for a remote attacker who somehow got LAN access remotely, they can probably deduce the location through other means (eg. using crowdsourced wifi databases).
- maxlin
I've used Kasa plugs for a long while and was not surprised that their API allowed relay control and basic info of them as long as you manage to get in the same internal network. It's local, so IMHO that is not just reasonable, it's desirable. I don't need to give my friends permission to toggle the lights manually either.
Routers having abnormal amount of zerodays, and not being fixed on the other hand is actually serious, unlike this.
Just a week ago I actually set up one of TP-link's new line of smartplugs (Tapo instead of the old Kasa), and for that I had to make an account. For actual security, I'd rather have an option to control them locally with zero additional authentication when you're already inside the network, instead of the cloud stuff. But I HAD to make an account even though the custom code I control said plug with only accesses the plug locally.
- nubinetwork
The fact that a firmware upgrade bricked the camera doesn't bode well for their other products...
- ericpauley
A shocking number of devices are continuously reporting location data over random unencrypted protocols. What’s worse, they’re often sending the data to cloud IPs that aren’t even controlled by the company, so some random person is getting your real-time location.