Description
Kasa EC70 v4
and EC71 v4 do not logically disable the production debug interface at the
firmware or chip level and do not lock the bootloader.  Although the debug traces are physically
severed during manufacturing, an attacker with physical access can restore the
connection, interrupt the boot process, and manipulate boot parameters to enter
a non-standard initialization path that exposes an unauthenticated root shell
during startup.









Successful exploitation may allow an
attacker with physical access to obtain root-level command access during device
startup, resulting in loss of confidentiality, integrity, and availability for
the affected device. Exploitation requires device disassembly, restoration of
the severed debug connection, and manipulation of the boot process.
Published: 2026-10-01
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Tp-link
Tp-link kasa Ec70 V4
Tp-link kasa Ec71 V4
Vendors & Products Tp-link
Tp-link kasa Ec70 V4
Tp-link kasa Ec71 V4

Thu, 01 Oct 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 01 Oct 2026 21:00:00 +0000

Type Values Removed Values Added
Description Kasa EC70 v4 and EC71 v4 do not logically disable the production debug interface at the firmware or chip level and do not lock the bootloader.  Although the debug traces are physically severed during manufacturing, an attacker with physical access can restore the connection, interrupt the boot process, and manipulate boot parameters to enter a non-standard initialization path that exposes an unauthenticated root shell during startup. Successful exploitation may allow an attacker with physical access to obtain root-level command access during device startup, resulting in loss of confidentiality, integrity, and availability for the affected device. Exploitation requires device disassembly, restoration of the severed debug connection, and manipulation of the boot process.
Title Physical UART Access Leading to an Unauthenticated Root Shell in TP-Link Kasa EC70 and EC71
Weaknesses CWE-1191
References
Metrics cvssV4_0

{'score': 5.4, 'vector': 'CVSS:4.0/AV:P/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Tp-link Kasa Ec70 V4 Kasa Ec71 V4
cve-icon MITRE

Status: PUBLISHED

Assigner: TPLink

Published:

Updated: 2026-10-01T21:01:44.613Z

Reserved: 2026-09-28T23:32:02.361Z

Link: CVE-2026-102370

cve-icon Vulnrichment

Updated: 2026-10-01T21:01:41.059Z

cve-icon NVD

Status : Deferred

Published: 2026-10-01T21:17:17.703

Modified: 2026-10-02T18:47:49.947

Link: CVE-2026-102370

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T14:47:17Z

Weaknesses
  • CWE-1191

    On-Chip Debug and Test Interface With Improper Access Control