CVE-2026-13230

MEDIUM

TP-Link Kasa EC70 and EC71 Local Discovery - Unauthenticated Geolocation Disclosure

Title source: manual
STIX 2.1

Description

An information disclosure vulnerability was identified in TP-Link Kasa EC70 v4 and EC71 v4 in the local discovery mechanism, which exposes sensitive geolocation information without requiring authentication. This issue allows an attacker on the same local network to retrieve geolocation-related data through crafted responses. The vulnerability impacts confidentiality only, with no evidence of integrity of availability impact.

Scores

CVSS v4 5.3
EPSS 0.0026
EPSS Percentile 17.7%
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-200
Status published
Products (2)
TP-Link Systems Inc./Kasa EC70 v4 < 2.4.1 Build 20260621 rel.76536
TP-Link Systems Inc./Kasa EC71 v4 < 2.4.1 Build 20260621 rel.76536
Published Jul 15, 2026
Tracked Since Jul 15, 2026