DigiNews

Tech Watch by Johan Denoyer

← Back to articles

TP-Link Kasa EC71 Security Advisory: GPS exposure, fleet-wide keys, and insecure credentials

Quality: 8/10 Relevance: 9/10

Summary

A detailed security advisory analysis of TP-Link Kasa EC71 cameras, focusing on hardcoded fleet-wide RSA keys, insecure storage of user credentials, and unauthenticated GPS exposure via port 9999. The report covers CVE-2026-9770 and CVE-2026-13230, remediation in firmware 2.4.1, and a beta rollout with a complete disclosure timeline and secondary market risk. It highlights privacy and cross-domain impact, including potential access to home coordinates and TP-Link ecosystem credentials.

🚀 Service construit par Johan Denoyer