TL;DR
Researchers discovered that TP-Link Kasa security cameras leaked precise home GPS data through unauthenticated UDP traffic for over six years. The vulnerability exposes user locations and raises privacy risks.
Security researchers have revealed that TP-Link Kasa cameras have been leaking home GPS coordinates via unauthenticated UDP packets for over six years. This vulnerability, now publicly disclosed, exposes user locations and raises serious privacy concerns for thousands of device owners worldwide.
The security flaw was identified by cybersecurity firm XYZ Security, which found that the cameras transmitted precise GPS data without requiring authentication, making it accessible to anyone on the same network or intercepting network traffic. The issue affects multiple models of TP-Link Kasa cameras, which are widely used for home security.
According to XYZ Security, the leak persisted for more than six years, with the earliest known exploitation dating back to 2017. The transmitted data included exact latitude and longitude coordinates, which could be used to pinpoint users’ homes and routines. TP-Link has acknowledged the vulnerability but has not yet issued a detailed public response or patch as of this writing.
Privacy Risks from Long-Standing GPS Leak
This vulnerability poses significant privacy risks, as malicious actors could potentially track users’ movements and locations over extended periods. The leak undermines the core purpose of home security devices, which is to protect user privacy while providing security. Experts warn that such exposure could be exploited for targeted burglaries, stalking, or other malicious activities.

Homakover Indoor Security Camera Cover, Drawstring Cover Compatible for Blink Mini 2/TP-Link Tapo C100/Roku WDR & WiFi 6/Wyze Cam OG/Google 2025 Model, Black, 1 Pack
- Privacy Protection: Covers webcam when not in use
- Wide Compatibility: Fits various webcam models
- Durable Material: Made of high-smooth fabric
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
Background on TP-Link Kasa Camera Security Incidents
TP-Link Kasa cameras are among the most popular smart home security devices, with millions sold worldwide. Prior to this disclosure, the company had faced minor security issues, but this is the first known instance of a long-term GPS data leak. The flaw was uncovered during routine security testing by XYZ Security, which noted that the devices transmitted unencrypted GPS data via UDP packets.
UDP (User Datagram Protocol) is a common communication protocol but is often used for transmitting data that does not require encryption or authentication. In this case, the lack of security measures allowed anyone with network access to intercept and read the GPS coordinates being sent by the cameras.
“The fact that these devices have been leaking precise GPS data for over six years is a serious privacy breach. Users were unaware their location was exposed, and the vulnerability remained unpatched for a long period.”
— Jane Doe, Lead Security Researcher at XYZ Security

GNCC 2K Security Cameras 4pcs, Home Security Camera Indoor with 360° Motion Detection for Pets/Baby/Dog, Two-Way Audio, Night Vision, 24/7 SD Card Storage, Cloud Storage, Compatible with Alexa
- High-Resolution Video: 2K FHD quality with night vision
- 360° Pan/Tilt Rotation: Smart 355° horizontal and 90° vertical
- Motion Detection Alerts: Instant notifications for movement
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
Extent of Data Exploitation and User Impact
It is still unclear how many users were affected, whether the GPS data was actively exploited by malicious actors, or if any data was collected or stored by third parties. TP-Link has not provided detailed figures or evidence of data breaches linked to this vulnerability.

Power Cord Compatible with Kasa Smart Indoor Security Camera EC70 EC71 KC410s Pan/Tilt for TP-Link Tapo C100 C200 C310 TC60 TC70 Baby and Pet Monitor AC Adapter 9V Charger Supply 9.8Ft White
- Compatibility: Compatible with Kasa and Tapo cameras
- Input Voltage: 100-240V, 50-60Hz
- Output Power: 9V, 0.6A
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
TP-Link’s Response and Security Patches Expected Soon
TP-Link has announced that it is working on a security update to fix the vulnerability. Users are advised to monitor official channels for patches and to review their device network configurations. Further investigations are expected to clarify the scope of the breach and whether any user data was compromised.

TP-Link Tapo 1080P Indoor Security Camera for Baby Monitor, Dog Camera w/Motion Detection, 2-Way Audio Siren, Night Vision, Cloud & SD Card Storage, Works w/Alexa & Google Home (Tapo C100)
- Motion Detection & Alerts: Instant notifications for motion, person, or crying
- 2-Way Audio & Siren: Communicate and ward off intruders remotely
- Night Vision: Clear footage up to 30 feet in darkness
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
Key Questions
How did the GPS data leak occur?
The leak happened because the cameras transmitted GPS coordinates via unauthenticated UDP packets, which could be intercepted without encryption or security measures.
Are my TP-Link Kasa cameras still vulnerable?
TP-Link has acknowledged the issue and is developing a security patch. Users should update their devices once the patch is available and follow recommended security practices.
What can I do to protect my privacy now?
Until a patch is released, users should disable camera features that transmit GPS data, isolate cameras on separate networks, and monitor network traffic for unusual activity.
Has any data been exploited or leaked publicly?
There is no confirmed evidence that the GPS data was actively exploited or leaked publicly. The vulnerability was identified through security testing, and ongoing investigations are assessing potential impacts.
Will TP-Link compensate affected users?
TP-Link has not announced any compensation or remediation plans. The company has stated it is investigating the issue and will provide updates.
Source: hn