CVE-2026-102370

Published: Ott 01, 2026 Last Modified: Ott 02, 2026
ExploitDB:
Other exploit source:
Google Dorks:
MEDIUM 5,4
Source: f23511db-6c3e-4e32-a477-6aa17d310630
Attack Vector: physical
Attack Complexity: low
Privileges Required: none
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A

Description

AI Translation Available

Kasa EC70 v4
and EC71 v4 do not logically disable the production debug interface at the
firmware or chip level and do not lock the bootloader.  Although the debug traces are physically
severed during manufacturing, an attacker with physical access can restore the
connection, interrupt the boot process, and manipulate boot parameters to enter
a non-standard initialization path that exposes an unauthenticated root shell
during startup.

Successful exploitation may allow an
attacker with physical access to obtain root-level command access during device
startup, resulting in loss of confidentiality, integrity, and availability for
the affected device. Exploitation requires device disassembly, restoration of
the severed debug connection, and manipulation of the boot process.

1191

On-Chip Debug and Test Interface With Improper Access Control

Stable
Common Consequences
Security Scopes Affected:
Confidentiality Authorization Integrity Access Control
Potential Impacts:
Read Application Data Read Memory Execute Unauthorized Code Or Commands Modify Memory Modify Application Data Bypass Protection Mechanism
Applicable Platforms
All platforms may be affected
View CWE Details
https://www.tp-link.com/us/support/download/ec70/v4/#Firmware-Release-Notes
https://www.tp-link.com/us/support/download/ec71/v4/#Firmware-Release-Notes
https://www.tp-link.com/us/support/faq/5324/