CVE-2026-13230

Severity CVSS v4.0:
MEDIUM
Type:
CWE-200 Information Leak / Disclosure
Publication date:
15/07/2026
Last modified:
06/08/2026

Description

An information disclosure vulnerability was identified in TP-Link Kasa EC70 v4 and EC71 v4 in the local discovery mechanism, which exposes<br /> sensitive geolocation information without requiring authentication. This issue<br /> allows an attacker on the same local network to retrieve geolocation-related<br /> data through crafted responses.<br /> <br /> The<br /> vulnerability impacts confidentiality only, with no evidence of integrity of<br /> availability impact.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:tp-link:kasa_ec70_firmware:*:*:*:*:*:*:*:* 2.4.1 (excluding)
cpe:2.3:h:tp-link:kasa_ec70:4.0:*:*:*:*:*:*:*
cpe:2.3:o:tp-link:kasa_ec71_firmware:*:*:*:*:*:*:*:* 2.4.1 (excluding)
cpe:2.3:h:tp-link:kasa_ec71:4.0:*:*:*:*:*:*:*