Description
Kasa EC70 v4
and EC71 v4 do not logically disable the production debug interface at the
firmware or chip level and do not lock the bootloader.  Although the debug traces are physically
severed during manufacturing, an attacker with physical access can restore the
connection, interrupt the boot process, and manipulate boot parameters to enter
a non-standard initialization path that exposes an unauthenticated root shell
during startup.









Successful exploitation may allow an
attacker with physical access to obtain root-level command access during device
startup, resulting in loss of confidentiality, integrity, and availability for
the affected device. Exploitation requires device disassembly, restoration of
the severed debug connection, and manipulation of the boot process.
Published: 2026-10-01
Score: 5.4 Medium
EPSS: n/a
KEV: No
Impact: Unauthenticated root shell via physical UART leading to full device compromise
Action: Apply Firmware Update
AI Analysis

Impact

TP‑Link Kasa EC70 V4 and EC71 V4 do not disable the production debug interface or lock the bootloader, allowing an attacker with physical access to restore the severed UART connection, interrupt the boot process, and alter boot parameters. This exposes an unauthenticated root shell during startup, enabling full compromise of confidentiality, integrity, and availability. The weakness is a form of improper definition of privilege controls (CWE‑1191).

Affected Systems

Devices affected are the TP‑Link Kasa EC70 V4 and the TP‑Link Kasa EC71 V4. Only users with physical access to the device can exploit the flaw, typically by disassembling the unit and re‑connecting the UART pins.

Risk and Exploitability

The CVSS score of 5.4 indicates medium severity, while no EPSS score is available. The vulnerability is not listed in the CISA KEV catalog. Because exploiting it requires physical manipulation of the hardware, the likelihood of an attack is low but not negligible. If an intruder can reach the device, they can gain root during boot and fully control the device.

Generated by OpenCVE AI on October 1, 2026 at 22:54 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest firmware version that disables the debug interface and locks the bootloader, as released by TP‑Link
  • Secure the device chassis to prevent unauthorized physical access or tampering with the UART headers
  • If a firmware update is not available, physically disconnect or cover the UART pins so that the debug interface cannot be accessed
  • Limit internal network access to the device and monitor for unauthorized boot events

Generated by OpenCVE AI on October 1, 2026 at 22:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 01 Oct 2026 21:00:00 +0000

Type Values Removed Values Added
Description Kasa EC70 v4 and EC71 v4 do not logically disable the production debug interface at the firmware or chip level and do not lock the bootloader.  Although the debug traces are physically severed during manufacturing, an attacker with physical access can restore the connection, interrupt the boot process, and manipulate boot parameters to enter a non-standard initialization path that exposes an unauthenticated root shell during startup. Successful exploitation may allow an attacker with physical access to obtain root-level command access during device startup, resulting in loss of confidentiality, integrity, and availability for the affected device. Exploitation requires device disassembly, restoration of the severed debug connection, and manipulation of the boot process.
Title Physical UART Access Leading to an Unauthenticated Root Shell in TP-Link Kasa EC70 and EC71
Weaknesses CWE-1191
References
Metrics cvssV4_0

{'score': 5.4, 'vector': 'CVSS:4.0/AV:P/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: TPLink

Published:

Updated: 2026-10-01T21:01:44.613Z

Reserved: 2026-09-28T23:32:02.361Z

Link: CVE-2026-102370

cve-icon Vulnrichment

Updated: 2026-10-01T21:01:41.059Z

cve-icon NVD

Status : Received

Published: 2026-10-01T21:17:17.703

Modified: 2026-10-01T22:17:00.393

Link: CVE-2026-102370

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T23:00:20Z

Weaknesses
  • CWE-1191

    On-Chip Debug and Test Interface With Improper Access Control