TL;DR
Independent researcher Christopher Childress, known as BadChemical, recently published a detailed advisory on the TP-Link Kasa Spot EC71 WiFi camera, revealing significant security flaws. His investigation involved extracting the firmware directly from the camera using a CH341A programmer and conducting a thorough analysis, which led to the discovery of three critical vulnerabilities now documented as CVEs (Common Vulnerabilities and Exposures).