Kasa EC70 v4 和 EC71 v4 固件及芯片层面未逻辑禁用生产调试接口,且未锁定引导加载程序(bootloader)。尽管在制造过程中物理断开了调试踪迹,但拥有物理访问权限的攻击者可以恢复该连接,中断启动过程,并操纵启动参数以进入非标准初始化路径,从而在设备启动期间暴露一个无需认证的 root 权限 shell。 成功利用该漏洞可使拥有物理访问权限的攻击者在设备启动阶段获得 root 级命令访问权限,导致受影响设备的机密性、完整性和可用性丧失。利用此漏洞需要对设备进行拆解、恢复已断开的调试连接,并操纵启
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| TP-Link Systems Inc. | Kasa EC70 V4 | < 2.4.3 Build 20260902 rel.4511 |
affected |
| TP-Link Systems Inc. | Kasa EC71 V4 | < 2.4.3 Build 20260902 rel.4511 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| TP-Link Systems Inc. | Kasa EC70 V4 | 0 ~ 2.4.3 Build 20260902 rel.4511 | - |
|
| TP-Link Systems Inc. | Kasa EC71 V4 | 0 ~ 2.4.3 Build 20260902 rel.4511 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-102369 | 8.7 HIGH | Unauthenticated Remote Code Execution via MacTool Command Injection in TP-Link Tapo C120 & |
| CVE-2026-8618 | 7.7 HIGH | Pre-Authentication Stack-based Buffer Overflow Remote Code Execution in TDDPv2 Subtype 0x9 |
| CVE-2026-84682 | 7.7 HIGH | TDDPv2 setProductVer Command Injection in Archer AX90 |
| CVE-2026-9032 | 7.1 HIGH | Unauthenticated Onboarding Connect NULL Pointer Dereference Denial of Service Vulnerabilit |
| CVE-2026-78578 | 7.1 HIGH | Unauthenticated do Method Onboarding Connect Allows Wi‑Fi Reconfiguration Denial of Servic |
| CVE-2026-78577 | 5.3 MEDIUM | Unauthenticated Onboarding Scan Information Disclosure in TP-Link Tapo C120 & C200 |
No comments yet