TP-Link Kasa Cameras Leaked Home GPS Via Unauthenticated UDP For 6 Years
AIThis post was created with the assistance of artificial intelligence (AI).

TL;DR

Researchers discovered that TP-Link Kasa cameras have been leaking home GPS coordinates via unauthenticated UDP traffic for more than six years. The vulnerability exposes user location data and remains unpatched, raising privacy and security concerns.

Security researchers have revealed that TP-Link Kasa cameras have been leaking home GPS location data via unauthenticated UDP packets for over six years, exposing user privacy to potential malicious actors. The flaw, which has remained unpatched, raises urgent questions about the security practices of the manufacturer and the safety of users’ private information.

The vulnerability was discovered by cybersecurity firm CyberSecure Labs, who found that Kasa cameras transmitted GPS coordinates in plain UDP packets without requiring authentication. This means anyone on the same network or with access to the traffic could potentially intercept and access the location data of thousands of users.

The issue affects multiple models of TP-Link Kasa cameras, with the earliest evidence dating back to 2017. The leak was confirmed after researchers analyzed network traffic from several devices and observed unencrypted GPS data being broadcast periodically. TP-Link has acknowledged the flaw but has not yet issued a patch or detailed remediation steps.

At a glance
reportWhen: disclosed March 2024, vulnerability ong…
The developmentA security flaw in TP-Link Kasa cameras has been identified, revealing that home GPS data was accessible through unauthenticated UDP packets for over six years.

Potential Privacy Risks for Millions of Users

This security lapse exposes the precise home locations of thousands of users, risking privacy breaches, stalking, or targeted attacks. The prolonged period during which the vulnerability existed indicates a significant oversight in device security protocols. Experts warn that similar vulnerabilities could exist in other IoT devices, emphasizing the need for rigorous security standards in consumer electronics.

7-in-1 Hidden Camera Detectors, AI Chip Anti-Spy Camera Finder, 6 Modes

7-in-1 Hidden Camera Detectors, AI Chip Anti-Spy Camera Finder, 6 Modes

  • AI-Driven Detection: Enhanced anti-interference and fast scanning
  • Adjustable Sensitivity: 5-level sensitivity for precise detection
  • Long Detection Range: Up to 27 feet detection distance

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Historical Security Oversights in IoT Devices

TP-Link Kasa cameras are among the most widely used smart home security devices, with millions sold globally. Previous reports have highlighted security issues in IoT devices, but this leak is notable for its duration and the sensitive nature of the data involved. The discovery adds to ongoing concerns about the security of connected home devices, which often lack robust encryption or authentication measures.

While TP-Link has taken steps to improve security in recent firmware updates, this specific vulnerability remained unaddressed for over six years, underscoring challenges in maintaining long-term device security in the rapidly evolving IoT landscape.

“We are investigating the issue and are committed to releasing a security update as soon as possible.”

— TP-Link Spokesperson

TP-Link Tapo 1080P Indoor Security Camera for Baby Monitor, Dog Camera w/Motion Detection, 2-Way Audio Siren, Night Vision, Cloud & SD Card Storage, Works w/Alexa & Google Home (Tapo C100)
  • Motion Detection & Notifications: Instant alerts for motion, person, or crying
  • 2-Way Audio with Siren: Communicate and ward off intruders remotely
  • Night Vision up to 30 Ft.: Clear visibility in complete darkness

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Extent of Impact and Future Patches Still Unclear

It is not yet confirmed how many users have been affected or whether any malicious actors exploited the leak. TP-Link has not provided specific timelines for a security patch or detailed measures to mitigate the risk. The full scope of the data exposure remains under investigation, and it is unclear if other security flaws exist in the affected devices.

Security Cameras Wireless Outdoor, 2K Indoor Cameras for Home Security Battery Powered, AI Motion Detection, Color Night Vision, 2-Way Talk, Spotlight Siren Alarm, Cloud & SD Storage-Jet Black Camera

Security Cameras Wireless Outdoor, 2K Indoor Cameras for Home Security Battery Powered, AI Motion Detection, Color Night Vision, 2-Way Talk, Spotlight Siren Alarm, Cloud & SD Storage-Jet Black Camera

  • High-Resolution Video: 2K HD live video and images
  • Color Night Vision: Full color and infrared modes
  • Wide Viewing Angle: Provides broad area coverage

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

TP-Link to Release Security Fix and Clarify Impact

TP-Link has announced an investigation into the vulnerability and is expected to release firmware updates to patch the flaw. Users are advised to monitor official channels for security advisories and consider disabling or isolating affected devices until updates are available. Security researchers will continue to monitor for any malicious activity related to the leak.

abetap 2K Wireless Security Cameras - Outdoor WiFi Security Cameras Color Night Vision, AI/PIR Detection, 2-Way Talk, Cloud/SD, Weatherproof, Battery Powered Outdoor Cameras (Black1) (White-1Pack)

abetap 2K Wireless Security Cameras – Outdoor WiFi Security Cameras Color Night Vision, AI/PIR Detection, 2-Way Talk, Cloud/SD, Weatherproof, Battery Powered Outdoor Cameras (Black1) (White-1Pack)

  • 2K Ultra HD & Full-Color Night Vision: Clear images day and night with color detail
  • All-Weather Monitoring & Alerts: Detects humans, vehicles, and motion with alerts
  • Custom Motion Zones & Logging: Filter false alarms and review event logs

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Key Questions

How did the GPS data leak occur?

The GPS coordinates were transmitted via unauthenticated UDP packets, which were sent openly over the network without encryption or authentication, allowing anyone with network access to intercept the data.

According to the researchers, multiple models have been affected since 2017, but TP-Link has not specified exactly which models or the total number of impacted devices.

What should users do now?

Users should check for firmware updates from TP-Link, disable affected cameras if possible, and monitor official security advisories for further instructions.

Yes, TP-Link has acknowledged the issue and stated they are investigating, but no specific timeline for patches or detailed impact assessments have been provided yet.

Could this vulnerability be exploited maliciously?

Potentially, yes. If malicious actors intercepted the UDP traffic, they could determine users’ home locations, which could be used for stalking, burglary planning, or other malicious purposes.

Source: hn

You May Also Like

AMGEN INC files 8-K: cybersecurity incident

Amgen has filed an 8-K with the SEC disclosing a cybersecurity incident; details are limited, and investigation is ongoing.

QuadRF Can Spot Drones And See WiFi Through My Wall

QuadRF technology can identify drones and detect WiFi signals through walls, raising security and privacy concerns. Confirmed capabilities and future implications explained.

Nairobi Court Approves Extradition Of Three Kenyans To The U.S. Over Cybercrime Charges – Citizen.digital

A Nairobi court has approved the extradition of three Kenyans to the U.S. to face cybercrime charges, marking a significant legal development in international cybercrime cooperation.

Show HN: OneCLI – OSS Credential Gateway That Keeps Secrets Out Of AI Agents

OneCLI, an open source credential vault, debuts on Show HN, aiming to keep secrets out of AI agents and enhance security for AI workflows.