6.5

CVE-2026-13230

Medienbericht

Information Disclosure Vulnerability in Local Discovery Response in TP-Link Kasa EC70 and EC71

An information disclosure vulnerability was identified in TP-Link Kasa EC70 v4 and EC71 v4 in the local discovery mechanism, which exposes
sensitive geolocation information without requiring authentication. This issue
allows an attacker on the same local network to retrieve geolocation-related
data through crafted responses.

The
vulnerability impacts confidentiality only, with no evidence of integrity of
availability impact.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Tp-link ≫ Kasa Ec70 Firmware Version < 2.4.1
   Tp-link ≫ Kasa Ec70 Version 4.0
Tp-link ≫ Kasa Ec71 Firmware Version < 2.4.1
   Tp-link ≫ Kasa Ec71 Version 4.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.38% 0.31
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.5 2.8 3.6
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
f23511db-6c3e-4e32-a477-6aa17d310630 5.3 0 0
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
03.08.2026 16:28
https://www.tp-link.com/us/support/download/ec71/#Firmware-Release-Notes
Release Notes
https://www.tp-link.com/en/support/download/ec71/#Firmware-Release-Notes
Release Notes
https://www.tp-link.com/us/support/download/ec70/v4/#Firmware-Release-Notes
Release Notes
https://www.tp-link.com/en/support/download/ec70/v4/#Firmware-Release-Notes
Release Notes
https://www.tp-link.com/us/support/faq/5192/
Vendor Advisory