TP-Link Kasa cameras leaked home GPS via unauthenticated UDP for 6 years
TP-Link Kasa摄像头因未经身份验证的UDP漏洞泄露家庭GPS信息长达6年
HN 102 分 · 21 条评论 · 作者 BadChemical · 来源 github.com · HN 讨论
【摘要】
CVE-2026-9770 and CVE-2026-13230 in TP-Link Kasa Spot EC71 firmware were patched in version 2.4.1, addressing critical vulnerabilities identified by researcher Christopher Childress. The original firmware version 2.3.26 contained fatal flaws including fleet-wide RSA key exposure, insecure credential storage, and unauthenticated GPS data leakage.
⋯ 继续阅读请登录会员 ⋯