6 ms·
TP-Link Kasa cameras leaked home GPS via unauthenticated UDP for 6 years
- BadChemical 3mo agoSix months of coordinated disclosure on a TP-Link Kasa camera resulted in two CVEs, a triage failure where the vendor described a vulnerability that doesn't exist in the reported payload, a beta patch that permanently bricked my test device, and a factory reset that doesn't clear previous owner data. The GPS finding (CVE-2026-13230) has been publicly documented on this device class since 2020. A single UDP packet returns sub-meter home coordinates with no authentication required. TP-Link scored it 5.3 medium. My independent assessment is 7.1 high. Precise home coordinates aren't low confidentiality impact. The credential finding (CVE-2026-9770) covers a fleet wide RSA key and unsalted MD5 TP-Link ID credentials. Same credentials provide global authentication across the TP-Link ecosystem. Factory reset on a secondhand device doesn't clear the data. Connecting to the device's soft AP during setup and sending a single UDP packet returns the previous owner's GPS coordinates.
- gruez 3mo agoThe report seems obviously AI generated, so I can't be bothered to read in its entirety, but based on my quick skim, "leaked home GPS" makes it sound worse than it is. Unless you're dumb enough to set DMZ on this device, this won't be exposed to the internet, and if it's LAN only, don't you already know the location? Even for a remote attacker who somehow got LAN access remotely, they can probably deduce the location through other means (eg. using crowdsourced wifi databases).
- forestry 3mo ago[flagged]
- wolvoleo 3mo agoA random post on hacker news isn't going to make a dent in TP-Link's camera marketshare positive or negative. If the GP really has bad motives they wouldn't really accomplish anything with that. But I doubt they do. I use these cams myself too. They're ok if you limit their internet access. I limit all my TP-Link stuff anyway since they suddenly removed local access for their switched power plugs in an auto firmware update. It's not the best company but they're cheap.
- lostmsu 3mo ago> since they suddenly removed local access for their switched power plugs in an auto firmware update. AFAIK it was because it was an unencrypted protocol and you can just manually turn it back on in device settings.
- justsomehnguy 3mo agoThere is only two ways to receive this unencrypted data: - to do the song and dance to allow the whole Internet to access this cam - and 'security professionals' have been advising no to do that no matter what vendor it is - to sit on your wire, literally and sniff everything Unencrypted personal data is not good but if you have a habit of leaving your car with the open doors, windows and a key in the ignition - don't run around telling horror stories what someone didn't close the lid on a cookie jar.
- fragmede 3mo agoThat's because you live in a shitty place where your can't do that with your car, and think that's normal. There are places in the world where you can just leave your car unlocked with cash sitting out, and no one steals it. Yeah, the Internet is not such a place, so we can't act that way here, but in the physical world, there are safe places where you can relax.
- drnick1 3mo agoThis underscores the principle that IoT devices should not be allowed to communicate over the public Internet. Pretty much all cheap, Chinese-made hardware of this kind has intentional or unintentional security holes waiting to be exploited.
- WarOnPrivacy 3mo ago> Pretty much all cheap, Chinese-made hardware of this kind has intentional or unintentional security holes waiting to be exploited. Why single out bad Chinese coding? Bad US IoT coding has a longer history.
- copperx 3mo agoAll of there IoT devices will be slop coded soon, and I wonder whether that will be an improvement or not. I bet that security will be better.
- shakna 3mo ago> I bet that security will be better. Not doxing myself, but... Company with a known name vibecoded a dashboard with Claude. Which also hardcoded a password into the client-side of the dashboard, which I caught. I reckon security will be about the same.
- fakwandi_priv 3mo agoWhen I'm reading reviews of plans created by an agent especially on security boundaries it's suggesting huge matrixes to test even the very obscure situations, but then I'm also reading things like this and I just don't understand. Are we even using the same tools?
- titularcomment 3mo ago1. It depends on model and tokens spent 2. Models talk the talk but not always walk the walk
- BobbyTables2 3mo agoThat disclosure timeline is brutal…
- AndyMcConachie 3mo agoWhy do people keep buying all this garbage and putting it in their homes?
- danparsonson 3mo agoBecause it's convenient and solves a problem and there's nothing better available for sensible money - maybe better to ask why no-one seems able or willing to make a product like this that isn't garbage?
- 1970-01-01 3mo agoThis. They want to watch their cats when they are out but have absolutely no clue about security. So they just buy whatever is cheapest on Amazon and if it works the problem is permanently solved in their world. China has no reason to stop cranking these out at the lowest price point.
- neogodless 3mo agoTP-Link in particular because you can throw in an SD card and pay no subscription cost for many of their cameras, while a lot of other brands require monthly commitments to use most of the features.
- nubinetwork 3mo agoThe fact that a firmware upgrade bricked the camera doesn't bode well for their other products...
- inigyou 3mo agoSome of those products are banned from import into the US and will be destroyed by customs at the border. Because they're so full of probably intentional backdoors.
- ericpauley 3mo agoA shocking number of devices are continuously reporting location data over random unencrypted protocols. What’s worse, they’re often sending the data to cloud IPs that aren’t even controlled by the company, so some random person is getting your real-time location.
- joshspankit 3mo agoDefinitely curious about the breakdown of data-broker relationship for each link in the chain. Unencrypted data is easy to store and share so it’s reasonable to assume that even the most stringent privacy policy for an IoT device is essentially meaningless if it’s unencrypted PII passes through a single tracking server (including the user’s ISP who may have a direct relationship with multiple brokers)
- ralphlarry 3mo ago[flagged]
- myshapeprotocol 3mo ago[flagged]
- ck2 3mo agobtw there is now open-source 3rd party firmware for some tp-link cameras from https://thingino.com https://thingino.com
- maxlin 3mo agoI've used Kasa plugs for a long while and was not surprised that their API allowed relay control and basic info of them as long as you manage to get in the same internal network. It's local, so IMHO that is not just reasonable, it's desirable. I don't need to give my friends permission to toggle the lights manually either. Routers having abnormal amount of zerodays, and not being fixed on the other hand is actually serious, unlike this. Just a week ago I actually set up one of TP-link's new line of smartplugs (Tapo instead of the old Kasa), and for that I had to make an account. For actual security, I'd rather have an option to control them locally with zero additional authentication when you're already inside the network, instead of the cloud stuff. But I HAD to make an account even though the custom code I control said plug with only accesses the plug locally.
- mlhpdx 3mo agoGood, they used UDP for a one off request /response (maybe) exchange. Bad, they included precise location information. I can see how rough location information is helpful for support and business information. Maybe country, maybe even zip code. But precise GPS was a bit overkill. Maybe it was easy, maybe it was nefarious, but not encrypting it over the wow was just plain dumb. I guess there is a razor for that. How would this exfiltration happen though? Aren’t these cameras going to be behind a firewall? Without a request originating internally no external packet will make it past, right? Does the firmware make the first request? If so, I missed it. I’m more mystified by the fleet wide certs. Old manufacturing tech that makes per-device firmware difficult, perhaps?
- BadChemical 3mo agoThe UDP is through the broken, since 2016, TP link smart home protol. Exfiltration would require a precursor network foothold for a pure network vector, or for local 2nd hand markets the data is returned from the device broadcasted AP which is used for account binding.