Introduction
TP-Link Kasa cameras have been found to have a significant vulnerability that exposes user locations. The cameras leak home GPS data via unauthenticated UDP requests, which can be exploited by attackers to obtain precise location information.
Vulnerability Details
The vulnerability, identified as CVE-2026-13230, allows attackers to send a single UDP packet to the camera's port 9999 and receive a JSON response containing the device's GPS coordinates, hardware identifiers, and other sensitive information [1]. This information can be used to identify the user's location and potentially compromise their privacy.
Impact
The impact of this vulnerability is significant, as it allows attackers to obtain precise location information without any authentication or authorization [2]. This can be particularly concerning for users who have placed these cameras in their homes, as it could potentially allow attackers to identify their location and compromise their safety.
Patch Availability
TP-Link has released patched firmware for the affected camera models, which can be updated via the official support pages [3]. Users are strongly advised to update their camera firmware as soon as possible to protect their locations and prevent potential exploitation.
Additional Findings
Additional research has found that the Kasa camera's firmware contains a hardcoded RSA private key, which can be extracted and used to compromise the device's security [4]. Furthermore, the camera's credential storage has been found to be insecure, using unsalted MD5 hashes that can be easily cracked [5].
Conclusion
The TP-Link Kasa camera vulnerability highlights the importance of ensuring the security of IoT devices. Users must be aware of the potential risks associated with these devices and take steps to protect themselves, such as regularly updating firmware and using strong passwords.
Sources
- CVE-2026-13230: TP-Link Kasa Camera GPS Data Leak
- TP-Link Kasa Camera Vulnerability: Unauthenticated GPS Data Leak
- TP-Link Official Support Pages: Firmware Updates
- Hardcoded RSA Private Key in TP-Link Kasa Camera Firmware
- Insecure Credential Storage in TP-Link Kasa Camera


