The LG TV network scanning story breaking today includes UDP 9999 Kasa discovery broadcasts every 25 seconds. That's the exact port I documented in CVE-2026-13230 as returning unauthenticated precise GPS coordinates from Kasa cameras with no authentication. Any LG TV + unpatched Kasa camera on the same network = GPS harvesting every 25 seconds. @briankrebs@infosec.exchange Advisory: https://github.com/BadChemical/IoT-Vulnerability-Research-Public/blob/main/TP-Link_Kasa_EC71/Kasa_EC71.md
Commenti (6)
@BadChemical@infosec.exchange @briankrebs@infosec.exchange Any Chinese product (which would be most products these days) that connects to the Internet is probably pwnable, security simply isn’t a priority because the vast majority of the people they sell to don’t know or care, and the market costs for bad security are zero.
The main business threat would be the Trump admin using security as an excuse for bans or tariffs, and paying him off directly is almost surely cheaper than investing in long-term security work 😔
@BadChemical@infosec.exchange @briankrebs@infosec.exchange if nothing else, how is this not a national security issue?
@BadChemical@infosec.exchange @briankrebs@infosec.exchange wow LG really are just fucking criminals, huh?
@BadChemical@infosec.exchange @briankrebs@infosec.exchange why every 25 seconds? my house doesn't move and I wouldn't expect my Kasa camera to move either
@BadChemical@infosec.exchange @briankrebs@infosec.exchange Wait, LG is using software the intentionally exploits a vulnerability? Is that not an instant CFAA violation?
I doubt the purpose of the scans is to acquire GPS coordinates. I think the scans serve some other purpose, but I don’t know what.
If they wanted GPS coordinates, they could have built in a GPS receiver. That would have been more reliable and attracts less attention.