CVE-2026-13230: Information Disclosure Vulnerability in Local Discovery Response in TP-Link Kasa EC70 and EC71
An information disclosure vulnerability was identified in TP-Link Kasa EC70 v4 and EC71 v4 in the local discovery mechanism, which exposes sensitive geolocation information without requiring authentication. This issue allows an attacker on the same local network to retrieve geolocation-related data through crafted responses.
The vulnerability impacts confidentiality only, with no evidence of integrity of availability impact.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-13230?
CVE-2026-13230 has a medium severity rating of 5.3 based on the CVSS score of 4.0.
What products are affected by CVE-2026-13230?
CVE-2026-13230 affects the TP-Link Kasa EC70 v4 and EC71 v4.
What type of vulnerability is described in CVE-2026-13230?
CVE-2026-13230 is classified as an information disclosure vulnerability.
How does CVE-2026-13230 affect users?
CVE-2026-13230 allows an attacker on the same local network to retrieve sensitive geolocation information without needing authentication.
How do I fix CVE-2026-13230?
To address CVE-2026-13230, update the firmware of your TP-Link Kasa EC70 and EC71 to the latest available version.