Serious flaws found in a popular WiFi camera
tech
Per Adafruit Blog, independent researcher Christopher Childress has published a detailed security advisory on the TP-Link Kasa Spot EC71 camera, and the findings reveal some genuinely alarming design choices. Childress uncovered three major vulnerabilities—all now assigned CVE numbers—that collectively could expose users' locations, cloud credentials, and smart home access. The first: a fleet-wide RSA private key, identical on every device. The second: cloud credentials stored as an unsalted MD5 hash with the email address sitting right there in plaintext. Third: a single UDP packet to port ninety-nine ninety-nine returns precise GPS coordinates protected by nothing more than a simple XOR cipher. Even worse, a factory reset doesn't clear any of these, meaning a secondhand Kasa Spot could hand its new owner the previous owner's location and login credentials. TP-Link has patched all three in firmware two point four point one.
Source: https://blog.adafruit.com/2026/07/20/serious-flaws-found-...
Listen to this story
Hear this and more stories in a personalized audio briefing.
Open The Chonkerton