Good, they used UDP for a one off request /response (maybe) exchange. Bad, they included precise location information.
I can see how rough location information is helpful for support and business information. Maybe country, maybe even zip code. But precise GPS was a bit overkill. Maybe it was easy, maybe it was nefarious, but not encrypting it over the wow was just plain dumb. I guess there is a razor for that.
How would this exfiltration happen though? Aren’t these cameras going to be behind a firewall? Without a request originating internally no external packet will make it past, right? Does the firmware make the first request? If so, I missed it.
I’m more mystified by the fleet wide certs. Old manufacturing tech that makes per-device firmware difficult, perhaps?
The UDP is through the broken, since 2016, TP link smart home protol. Exfiltration would require a precursor network foothold for a pure network vector, or for local 2nd hand markets the data is returned from the device broadcasted AP which is used for account binding.