Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-102370— Physical UART Access Leading to an Unauthenticated Root Shell in TP-Link Kasa EC70 and EC71

Quick assessment

Affected
TP-Link Systems Inc. Kasa EC70 V4
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Kasa EC70 v4 和 EC71 v4 固件及芯片层面未逻辑禁用生产调试接口,且未锁定引导加载程序(bootloader)。尽管在制造过程中物理断开了调试踪迹,但拥有物理访问权限的攻击者可以恢复该连接,中断启动过程,并操纵启动参数以进入非标准初始化路径,从而在设备启动期间暴露一个无需认证的 root 权限 shell。 成功利用该漏洞可使拥有物理访问权限的攻击者在设备启动阶段获得 root 级命令访问权限,导致受影响设备的机密性、完整性和可用性丧失。利用此漏洞需要对设备进行拆解、恢复已断开的调试连接,并操纵启

CVSS 5.4 · Medium EPSS 0.18% · P7

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application

Affected Version Matrix 2

VendorProduct Version RangeStatus
TP-Link Systems Inc. Kasa EC70 V4 < 2.4.3 Build 20260902 rel.4511 affected
TP-Link Systems Inc. Kasa EC71 V4 < 2.4.3 Build 20260902 rel.4511 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-102370

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Physical UART Access Leading to an Unauthenticated Root Shell in TP-Link Kasa EC70 and EC71
Source: CVE Program / CVE List V5
Vulnerability Description
Kasa EC70 v4 and EC71 v4 do not logically disable the production debug interface at the firmware or chip level and do not lock the bootloader.  Although the debug traces are physically severed during manufacturing, an attacker with physical access can restore the connection, interrupt the boot process, and manipulate boot parameters to enter a non-standard initialization path that exposes an unauthenticated root shell during startup. Successful exploitation may allow an attacker with physical access to obtain root-level command access during device startup, resulting in loss of confidentiality, integrity, and availability for the affected device. Exploitation requires device disassembly, restoration of the severed debug connection, and manipulation of the boot process.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:P/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
CWE-1191
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
TP-Link Systems Inc. Kasa EC70 V4 0 ~ 2.4.3 Build 20260902 rel.4511 -
TP-Link Systems Inc. Kasa EC71 V4 0 ~ 2.4.3 Build 20260902 rel.4511 -

II. Public POCs for CVE-2026-102370

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-102370

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-102370 (1)

Vendor Pages for CVE-2026-102370 (2)

Same Patch Batch · TP-Link Systems Inc. · 2026-10-01 · 7 CVEs total

CVE-2026-102369 8.7 HIGH Unauthenticated Remote Code Execution via MacTool Command Injection in TP-Link Tapo C120 &
CVE-2026-8618 7.7 HIGH Pre-Authentication Stack-based Buffer Overflow Remote Code Execution in TDDPv2 Subtype 0x9
CVE-2026-84682 7.7 HIGH TDDPv2 setProductVer Command Injection in Archer AX90
CVE-2026-9032 7.1 HIGH Unauthenticated Onboarding Connect NULL Pointer Dereference Denial of Service Vulnerabilit
CVE-2026-78578 7.1 HIGH Unauthenticated do Method Onboarding Connect Allows Wi‑Fi Reconfiguration Denial of Servic
CVE-2026-78577 5.3 MEDIUM Unauthenticated Onboarding Scan Information Disclosure in TP-Link Tapo C120 & C200

IV. Related Vulnerabilities

V. Comments for CVE-2026-102370

No comments yet


Leave a comment