Description
An information disclosure vulnerability was identified in TP-Link Kasa EC70 v4 and EC71 v4 in the local discovery mechanism, which exposes
sensitive geolocation information without requiring authentication. This issue
allows an attacker on the same local network to retrieve geolocation-related
data through crafted responses.

The
vulnerability impacts confidentiality only, with no evidence of integrity of
availability impact.
Published: 2026-07-15
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An information disclosure vulnerability (CWE-200) resides in the local discovery mechanism of TP-Link Kasa EC70 v4 and EC71 v4. The flaw allows an attacker on the same local network to obtain geolocation‑related data that the device transmits in response to crafted discovery queries, without the need for authentication. The primary impact is the exposure of confidential location information; there is no evidence of integrity or availability compromise.

Affected Systems

TP-Link Systems Inc. offers the affected devices as Kasa EC70 v4 and Kasa EC71 v4. These models are listed by the CNA as the only affected variants, and no additional revisions or firmware branches are mentioned in the supplied data.

Risk and Exploitability

The CVSS score of 5.3 reflects a medium severity vulnerability, and the EPSS value of less than 1 % indicates that the likelihood of automated exploitation is currently low. The vulnerability is not listed in CISA’s KEV catalog. Even so, the attack vector is fairly straightforward: any malicious host on the same local network could send crafted discovery packets and capture the geolocation response. As authentication is not required, the exploitation can occur without administrative credentials.

Generated by OpenCVE AI on July 31, 2026 at 04:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Acquire and install the latest firmware from TP-Link’s support site for model EC70 v4 or EC71 v4
  • Configure a local firewall or router to block or restrict untrusted devices from sending discovery packets to the Kasa devices
  • Segment the network so that only trusted management devices can reach the Kasa devices, reducing exposure of the discovery service

Generated by OpenCVE AI on July 31, 2026 at 04:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
First Time appeared Tp-link
Tp-link kasa Ec70 V4
Tp-link kasa Ec71 V4
Vendors & Products Tp-link
Tp-link kasa Ec70 V4
Tp-link kasa Ec71 V4

Wed, 15 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 15 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
Description An information disclosure vulnerability was identified in TP-Link Kasa EC70 v4 and EC71 v4 in the local discovery mechanism, which exposes sensitive geolocation information without requiring authentication. This issue allows an attacker on the same local network to retrieve geolocation-related data through crafted responses. The vulnerability impacts confidentiality only, with no evidence of integrity of availability impact.
Title Information Disclosure Vulnerability in Local Discovery Response in TP-Link Kasa EC70 and EC71
Weaknesses CWE-200
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Tp-link Kasa Ec70 V4 Kasa Ec71 V4
cve-icon MITRE

Status: PUBLISHED

Assigner: TPLink

Published:

Updated: 2026-07-15T12:37:09.376Z

Reserved: 2026-06-24T17:50:08.263Z

Link: CVE-2026-13230

cve-icon Vulnrichment

Updated: 2026-07-15T12:37:04.068Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T04:15:04Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor