CVE-2026-102370
Received Received - Intake

Physical Debug Interface Access in Kasa EC70 v4 and EC71 v4

Vulnerability report for CVE-2026-102370, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: TPLink

Description

Kasa EC70 v4 and EC71 v4 do not logically disable the production debug interface at the firmware or chip level and do not lock the bootloader.Β  Although the debug traces are physically severed during manufacturing, an attacker with physical access can restore the connection, interrupt the boot process, and manipulate boot parameters to enter a non-standard initialization path that exposes an unauthenticated root shell during startup. Successful exploitation may allow an attacker with physical access to obtain root-level command access during device startup, resulting in loss of confidentiality, integrity, and availability for the affected device. Exploitation requires device disassembly, restoration of the severed debug connection, and manipulation of the boot process.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
kasa ec70 v4
kasa ec71 v4

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1191 The chip does not implement or does not correctly perform access control to check whether users are authorized to access internal registers and test modes through the physical debug/test interface.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects Kasa EC70 v4 and EC71 v4 devices. The debug interface is not disabled at firmware or chip level and the bootloader is not locked. An attacker with physical access can restore a severed debug connection, interrupt the boot process, and manipulate boot parameters to gain an unauthenticated root shell during startup.

Detection Guidance

Detection requires physical inspection of the device. Check if the debug traces are physically severed. If not, an attacker could restore the connection. No network commands can detect this as it requires physical access and manipulation.

Impact Analysis

Exploitation requires physical access, device disassembly, and boot process manipulation. Successful exploitation may allow an attacker to gain root-level command access during startup, leading to loss of confidentiality, integrity, and availability for the affected device.

Compliance Impact

This vulnerability allows attackers with physical access to gain root-level command access during device startup, potentially compromising confidentiality, integrity, and availability of the device. This could lead to unauthorized access to sensitive data, violating compliance requirements under standards like GDPR and HIPAA which mandate strict protection of personal and health information.

Mitigation Strategies

Physically secure devices to prevent unauthorized access. Ensure debug interfaces are permanently disabled or physically severed. Regularly inspect devices for tampering. No software mitigation is available as the issue is hardware-based.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102370. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart