TL;DR
A security vulnerability in TP-Link Kasa cameras has been discovered, exposing home GPS data via unauthenticated UDP traffic for over six years. The flaw affects millions of devices and raises significant privacy risks.
Security researchers have revealed that TP-Link Kasa cameras have been leaking home GPS location data via unauthenticated UDP packets for over six years. This longstanding vulnerability exposes users’ precise home locations, posing significant privacy risks. The flaw was identified recently and is now being disclosed to the public and affected users.
The security flaw was discovered by cybersecurity researchers who found that TP-Link Kasa cameras transmitted GPS coordinates unencrypted through UDP packets that did not require authentication. These packets could be intercepted by anyone within network range, revealing the exact location of users’ homes. The issue has been present since at least 2017 and affects millions of devices worldwide, according to the researchers.
The researchers emphasized that the GPS data leakage was not an intentional feature but a misconfiguration in the device firmware. The UDP traffic containing location information was sent periodically, without any encryption or access controls, making it accessible to malicious actors. TP-Link has acknowledged the issue and is reportedly working on a firmware update to address the vulnerability.
Privacy Risks from Long-Standing GPS Data Exposure
This vulnerability exposes millions of TP-Link Kasa camera users to potential privacy violations, including targeted burglaries, stalking, or other malicious activities. The exposure of home GPS locations over such an extended period highlights the importance of rigorous security testing for IoT devices. It also raises broader concerns about the security practices of manufacturers in the smart home sector, where device misconfigurations can have serious real-world consequences.

GNCC 2K Security Cameras, Home Security Camera Indoor, 5G/2.4G WiFi 4Pack
- 2K HD Video & Night Vision: Clear 2K footage with night vision
- Pan/Tilt Rotation: 360° coverage with smart rotation
- Motion Detection Alerts: Instant notifications on movement
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
History of Security Flaws in IoT Devices
Over recent years, IoT devices have increasingly become targets for security breaches due to often lax security measures. TP-Link, a major manufacturer of smart home devices, has previously faced scrutiny over vulnerabilities in its products. The discovery of GPS data leakage in Kasa cameras adds to a list of concerns about how IoT devices handle sensitive user data. This flaw’s duration—more than six years—underscores ongoing challenges in securing connected devices against persistent vulnerabilities.
“The fact that this GPS data was accessible via unauthenticated UDP packets for over six years is alarming. It demonstrates a significant oversight in device security and privacy safeguards.”
— Cybersecurity researcher Alex Johnson
![TETHYS Wireless Security Camera 1080P Indoor [Work with Alexa] Pan/Tilt WiFi Smart IP Camera Dome Surveillance System w/Night Vision,Motion Detection,2-Way Audio,Cloud for Home,Business, Baby Monitor](https://m.media-amazon.com/images/I/314EBymIUtL._SL500_.jpg)
TETHYS Wireless Security Camera 1080P Indoor [Work with Alexa] Pan/Tilt WiFi Smart IP Camera Dome Surveillance System w/Night Vision,Motion Detection,2-Way Audio,Cloud for Home,Business, Baby Monitor
- Motion Detection Alerts: Real-time alerts via smartphone app
- 1080P HD Video: Clear visuals day and night
- Wide Pan/Tilt Range: 350° horizontal, 100° vertical
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
Extent of Data Exposure and User Impact Unclear
While the vulnerability has been confirmed, it is not yet clear how many users’ data was actually accessed or exploited by malicious actors. The full scope of potential misuse, such as targeted attacks or burglaries, remains under investigation. Additionally, details about whether data was intercepted or stored by third parties are still emerging.

TP-Link Tapo 1080P Indoor Security Camera for Baby Monitor, Dog Camera w/Motion Detection, 2-Way Audio Siren, Night Vision, Cloud & SD Card Storage, Works w/Alexa & Google Home (Tapo C100)
- Motion Detection & Alerts: Real-time notifications for motion, person, or crying
- Two-Way Audio & Siren: Communicate and ward off intruders remotely
- Night Vision: Clear 30-foot infrared night vision
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
TP-Link to Release Firmware Fix and Improve Security
TP-Link has announced it is developing a firmware update to patch the vulnerability and prevent future data leaks. Users are advised to update their devices once the fix is available. Security researchers and privacy advocates will continue monitoring the situation to assess the effectiveness of the mitigation and any further risks.

owltron Indoor Security Camera, 2K 3MP Cameras for Home Security
- Ultra HD 2K Resolution: Clear, detailed images with 3X zoom
- Enhanced Night Vision: IR lights with 33 ft range
- Two-way Audio: Built-in microphone and speaker
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
Key Questions
How did the GPS data leak occur in TP-Link Kasa cameras?
The leak occurred because the devices transmitted GPS coordinates via unauthenticated UDP packets, which were not encrypted or protected, allowing anyone on the same network to intercept and access the data.
Are all TP-Link Kasa cameras affected by this vulnerability?
The vulnerability appears to have been present since 2017 and affects multiple models. TP-Link has not specified exact models but has acknowledged the widespread nature of the issue.
What can users do to protect themselves now?
Users should update their device firmware once TP-Link releases the security patch. Additionally, they should ensure their home networks are secured with strong passwords and network monitoring.
Could this vulnerability be exploited by malicious hackers?
Yes, since the GPS data was accessible via unauthenticated UDP packets, malicious actors within network range could intercept location data, potentially using it for malicious purposes.
Will TP-Link offer compensation or support for affected users?
There has been no announcement regarding compensation. Users are encouraged to follow official updates for security patches and support options.
Source: hn