5.4
CVE-2026-102370
- EPSS 0.18%
- Veröffentlicht 01.10.2026 20:47:30
- Zuletzt bearbeitet 02.10.2026 18:47:49
- Erkennungen
Physical UART Access Leading to an Unauthenticated Root Shell in TP-Link Kasa EC70 and EC71
Kasa EC70 v4 and EC71 v4 do not logically disable the production debug interface at the firmware or chip level and do not lock the bootloader. Although the debug traces are physically severed during manufacturing, an attacker with physical access can restore the connection, interrupt the boot process, and manipulate boot parameters to enter a non-standard initialization path that exposes an unauthenticated root shell during startup. Successful exploitation may allow an attacker with physical access to obtain root-level command access during device startup, resulting in loss of confidentiality, integrity, and availability for the affected device. Exploitation requires device disassembly, restoration of the severed debug connection, and manipulation of the boot process.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerTP-Link Systems Inc.
≫
Produkt
Kasa EC70 V4
Default Statusunaffected
Version
0
Version <
2.4.3 Build 20260902 rel.4511
Status
affected
HerstellerTP-Link Systems Inc.
≫
Produkt
Kasa EC71 V4
Default Statusunaffected
Version
0
Version <
2.4.3 Build 20260902 rel.4511
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.18% | 0.067 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| f23511db-6c3e-4e32-a477-6aa17d310630 | 5.4 | 0 | 0 |
CVSS:4.0/AV:P/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
CWE-1191 On-Chip Debug and Test Interface With Improper Access Control
The chip does not implement or does not correctly perform access control to check whether users are authorized to access internal registers and test modes through the physical debug/test interface.
https://www.tp-link.com/us/support/download/ec70/v4/#Firmware-Release-Notes
https://www.tp-link.com/us/support/download/ec71/v4/#Firmware-Release-Notes
https://www.tp-link.com/us/support/faq/5324/