Impact
An information disclosure vulnerability (CWE-200) resides in the local discovery mechanism of TP-Link Kasa EC70 v4 and EC71 v4. The flaw allows an attacker on the same local network to obtain geolocation‑related data that the device transmits in response to crafted discovery queries, without the need for authentication. The primary impact is the exposure of confidential location information; there is no evidence of integrity or availability compromise.
Affected Systems
TP-Link Systems Inc. offers the affected devices as Kasa EC70 v4 and Kasa EC71 v4. These models are listed by the CNA as the only affected variants, and no additional revisions or firmware branches are mentioned in the supplied data.
Risk and Exploitability
The CVSS score of 5.3 reflects a medium severity vulnerability, and the EPSS value of less than 1 % indicates that the likelihood of automated exploitation is currently low. The vulnerability is not listed in CISA’s KEV catalog. Even so, the attack vector is fairly straightforward: any malicious host on the same local network could send crafted discovery packets and capture the geolocation response. As authentication is not required, the exploitation can occur without administrative credentials.
OpenCVE Enrichment