Impact
TP‑Link Kasa EC70 V4 and EC71 V4 do not disable the production debug interface or lock the bootloader, allowing an attacker with physical access to restore the severed UART connection, interrupt the boot process, and alter boot parameters. This exposes an unauthenticated root shell during startup, enabling full compromise of confidentiality, integrity, and availability. The weakness is a form of improper definition of privilege controls (CWE‑1191).
Affected Systems
Devices affected are the TP‑Link Kasa EC70 V4 and the TP‑Link Kasa EC71 V4. Only users with physical access to the device can exploit the flaw, typically by disassembling the unit and re‑connecting the UART pins.
Risk and Exploitability
The CVSS score of 5.4 indicates medium severity, while no EPSS score is available. The vulnerability is not listed in the CISA KEV catalog. Because exploiting it requires physical manipulation of the hardware, the likelihood of an attack is low but not negligible. If an intruder can reach the device, they can gain root during boot and fully control the device.
OpenCVE Enrichment