Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-13230

An information disclosure vulnerability was identified in TP-Link Kasa EC70 v4 and EC71 v4 in the local discovery mechanism, which exposes sensitive geolocation information without requiring authentication. This issue allows an attacker on the same local network to retrieve geolocation-related data through crafted responses. The vulnerability impacts confidentiality only, with no evidence of integrity of availability impact.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 31.1%
CVSS Severity
CVSS v3 Score 6.5
Products affected by CVE-2026-13230


Contact Us

Shodan ® - All rights reserved