CVE-2026-13230 Details
Description
An information disclosure vulnerability was identified in TP-Link Kasa EC70 v4 and EC71 v4 in the local discovery mechanism, which exposes sensitive geolocation information without requiring authentication. This issue allows an attacker on the same local network to retrieve geolocation-related data through crafted responses. The vulnerability impacts confidentiality only, with no evidence of integrity of availability impact.
A vulnerability allowing information disclosure has been identified in the TP-Link Kasa EC70 v4 and EC71 v4 models. This issue arises in the local discovery mechanism, which exposes sensitive geolocation data without requiring authentication. An attacker on the same local network can exploit this vulnerability by sending crafted responses to retrieve geolocation-related information. The vulnerability impacts confidentiality by exposing sensitive location data, with no known effects on integrity or availability.
Users are advised to update to the latest firmware version. The patched version for both the Kasa EC70 and EC71 is 2.4.0 Build 20260520 or 2.4.1 Build 20260621. Instructions for downloading the firmware are available on the TP-Link website.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 15, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.tp-link.com/en/support/download/ec70/v4/#Firmware-Release-Notes | TPLink | Release Notes |
| https://www.tp-link.com/en/support/download/ec71/#Firmware-Release-Notes | TPLink | Release Notes |
| https://www.tp-link.com/us/support/download/ec70/v4/#Firmware-Release-Notes | TPLink | Release Notes |
| https://www.tp-link.com/us/support/download/ec71/#Firmware-Release-Notes | TPLink | Release Notes |
| https://www.tp-link.com/us/support/faq/5192/ | TPLink | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | TPLink |
Affected Products
| Product | Versions |
|---|---|
| tp-link kasa ec70 firmware | < 2.4.1 |
CPE
Remediation
| |
| tp-link kasa ec70 | 4.0 |
CPE
Remediation
| |
| tp-link kasa ec71 firmware | < 2.4.1 |
CPE
Remediation
| |
| tp-link kasa ec71 | 4.0 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 6, 2026 | Initial Analysis | [email protected] |
| Jul 15, 2026 | CVE Modified | CISA-ADP |
| Jul 15, 2026 | New CVE Received | TPLink |