CVE-2026-13230
MEDIUMTP-Link Kasa EC70 and EC71 Local Discovery - Unauthenticated Geolocation Disclosure
Title source: manualDescription
An information disclosure vulnerability was identified in TP-Link Kasa EC70 v4 and EC71 v4 in the local discovery mechanism, which exposes sensitive geolocation information without requiring authentication. This issue allows an attacker on the same local network to retrieve geolocation-related data through crafted responses. The vulnerability impacts confidentiality only, with no evidence of integrity of availability impact.
References (5)
Core 5
Core References
Vendor Advisory vendor-advisory
https://www.tp-link.com/us/support/faq/5192/
Scores
CVSS v4
5.3
EPSS
0.0026
EPSS Percentile
17.7%
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-200
Status
published
Products (2)
TP-Link Systems Inc./Kasa EC70 v4
< 2.4.1 Build 20260621 rel.76536
TP-Link Systems Inc./Kasa EC71 v4
< 2.4.1 Build 20260621 rel.76536
Published
Jul 15, 2026
Tracked Since
Jul 15, 2026