{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-13230","assignerOrgId":"f23511db-6c3e-4e32-a477-6aa17d310630","state":"PUBLISHED","assignerShortName":"TPLink","dateReserved":"2026-06-24T17:50:08.263Z","datePublished":"2026-07-15T00:21:16.177Z","dateUpdated":"2026-07-15T12:37:09.376Z"},"containers":{"cna":{"providerMetadata":{"orgId":"f23511db-6c3e-4e32-a477-6aa17d310630","shortName":"TPLink","dateUpdated":"2026-07-15T00:21:16.177Z"},"title":"Information Disclosure Vulnerability in Local Discovery Response in TP-Link Kasa EC70 and EC71","problemTypes":[{"descriptions":[{"lang":"en","cweId":"CWE-200","description":"CWE-200 Exposure of Sensitive Information to an Unauthorized Actor","type":"CWE"}]}],"impacts":[{"capecId":"CAPEC-118","descriptions":[{"lang":"en","value":"CAPEC-118 Collect & Analyze Information"}]}],"affected":[{"vendor":"TP-Link Systems Inc.","product":"Kasa EC71 v4","platforms":["NVMP"],"versions":[{"status":"affected","version":"0","lessThan":"2.4.1 Build 20260621 rel.76536","versionType":"custom"}],"defaultStatus":"unaffected"},{"vendor":"TP-Link Systems Inc.","product":"Kasa EC70 v4","platforms":["NVMP"],"versions":[{"status":"affected","version":"0","lessThan":"2.4.1 Build 20260621 rel.76536","versionType":"custom"}],"defaultStatus":"unaffected"}],"descriptions":[{"lang":"en","value":"An information disclosure vulnerability was identified in TP-Link Kasa EC70 v4 and EC71 v4 in the local discovery mechanism, which exposes\nsensitive geolocation information without requiring authentication. This issue\nallows an attacker on the same local network to retrieve geolocation-related\ndata through crafted responses.\n\nThe\nvulnerability impacts confidentiality only, with no evidence of integrity of\navailability impact.","supportingMedia":[{"type":"text/html","base64":false,"value":"An information disclosure vulnerability was identified in TP-Link Kasa EC70 v4 and EC71 v4 in the local discovery mechanism, which&nbsp;<span>exposes\nsensitive geolocation information without requiring authentication. This issue\nallows an attacker on the same local network to retrieve geolocation-related\ndata through crafted responses.</span><div><p>The\nvulnerability impacts confidentiality only, with no evidence of integrity of\navailability impact.</p></div>"}]}],"references":[{"url":"https://www.tp-link.com/us/support/download/ec71/#Firmware-Release-Notes","tags":["patch"]},{"url":"https://www.tp-link.com/en/support/download/ec71/#Firmware-Release-Notes","tags":["patch"]},{"url":"https://www.tp-link.com/us/support/download/ec70/v4/#Firmware-Release-Notes","tags":["patch"]},{"url":"https://www.tp-link.com/en/support/download/ec70/v4/#Firmware-Release-Notes","tags":["patch"]},{"url":"https://www.tp-link.com/us/support/faq/5192/","tags":["vendor-advisory"]}],"metrics":[{"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}],"cvssV4_0":{"attackVector":"ADJACENT","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"LOW","subConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE","subIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED","version":"4.0","baseSeverity":"MEDIUM","baseScore":5.3,"vectorString":"CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"}}],"credits":[{"lang":"en","value":"Christopher Childress","type":"finder"}],"source":{"discovery":"UNKNOWN"},"x_generator":{"engine":"Vulnogram 1.0.2"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-07-15T12:36:57.835701Z","id":"CVE-2026-13230","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-07-15T12:37:09.376Z"}}]}}