Physical UART Access Leading to an Unauthenticated Root Shell in TP-Link Kasa EC70 and EC71
Published Oct 1, 2026
5.4
MEDIUMCVSS 4.0
Description
Kasa EC70 v4 and EC71 v4 do not logically disable the production debug interface at the firmware or chip level and do not lock the bootloader. Although the debug traces are physically severed during manufacturing, an attacker with physical access can restore the connection, interrupt the boot process, and manipulate boot parameters to enter a non-standard initialization path that exposes an unauthenticated root shell during startup.
Successful exploitation may allow an attacker with physical access to obtain root-level command access during device startup, resulting in loss of confidentiality, integrity, and availability for the affected device. Exploitation requires device disassembly, restoration of the severed debug connection, and manipulation of the boot process.
Affected products
-
- Version 0StatusaffectedConstraints<2.4.3 Build 20260902 rel.4511
- Version
-
- Version 0StatusaffectedConstraints<2.4.3 Build 20260902 rel.4511
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| TP-Link Systems Inc. | Kasa EC70 V4 | unaffected |
| ||||||
| TP-Link Systems Inc. | Kasa EC71 V4 | unaffected |
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
CVSS:4.0/AV:P/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed Oct 1, 2026 · SSVC 2.0.3
No EPSS score for this CVE.
References (3)
Change history (0)
No recorded changes yet.