{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2026-102370",
        "assignerOrgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
        "state": "PUBLISHED",
        "assignerShortName": "TPLink",
        "dateReserved": "2026-09-28T23:32:02.361Z",
        "datePublished": "2026-10-01T20:47:30.211Z",
        "dateUpdated": "2026-10-01T21:01:44.613Z"
    },
    "containers": {
        "cna": {
            "providerMetadata": {
                "orgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
                "shortName": "TPLink",
                "dateUpdated": "2026-10-01T20:47:30.211Z"
            },
            "title": "Physical UART Access Leading to an Unauthenticated Root Shell in TP-Link Kasa EC70 and EC71",
            "problemTypes": [
                {
                    "descriptions": [
                        {
                            "lang": "en",
                            "cweId": "CWE-1191",
                            "description": "CWE-1191 On-Chip debug and test interface with improper access control",
                            "type": "CWE"
                        }
                    ]
                }
            ],
            "impacts": [
                {
                    "capecId": "CAPEC-116",
                    "descriptions": [
                        {
                            "lang": "en",
                            "value": "CAPEC-116 Excavation"
                        }
                    ]
                }
            ],
            "affected": [
                {
                    "vendor": "TP-Link Systems Inc.",
                    "product": "Kasa EC70 V4",
                    "versions": [
                        {
                            "status": "affected",
                            "version": "0",
                            "lessThan": "2.4.3 Build 20260902 rel.4511",
                            "versionType": "custom"
                        }
                    ],
                    "defaultStatus": "unaffected"
                },
                {
                    "vendor": "TP-Link Systems Inc.",
                    "product": "Kasa EC71 V4",
                    "versions": [
                        {
                            "status": "affected",
                            "version": "0",
                            "lessThan": "2.4.3 Build 20260902 rel.4511",
                            "versionType": "custom"
                        }
                    ],
                    "defaultStatus": "unaffected"
                }
            ],
            "descriptions": [
                {
                    "lang": "en",
                    "value": "Kasa EC70 v4\nand EC71 v4 do not logically disable the production debug interface at the\nfirmware or chip level and do not lock the bootloader.  Although the debug traces are physically\nsevered during manufacturing, an attacker with physical access can restore the\nconnection, interrupt the boot process, and manipulate boot parameters to enter\na non-standard initialization path that exposes an unauthenticated root shell\nduring startup.\n\n\n\n\n\n\n\n\n\nSuccessful exploitation may allow an\nattacker with physical access to obtain root-level command access during device\nstartup, resulting in loss of confidentiality, integrity, and availability for\nthe affected device. Exploitation requires device disassembly, restoration of\nthe severed debug connection, and manipulation of the boot process.",
                    "supportingMedia": [
                        {
                            "type": "text/html",
                            "base64": false,
                            "value": "<p>Kasa EC70 v4\nand EC71 v4 do not logically disable the production debug interface at the\nfirmware or chip level and do not lock the bootloader.&nbsp; Although the debug traces are physically\nsevered during manufacturing, an attacker with physical access can restore the\nconnection, interrupt the boot process, and manipulate boot parameters to enter\na non-standard initialization path that exposes an unauthenticated root shell\nduring startup.</p><p>\n\n</p><p>Successful exploitation may allow an\nattacker with physical access to obtain root-level command access during device\nstartup, resulting in loss of confidentiality, integrity, and availability for\nthe affected device. Exploitation requires device disassembly, restoration of\nthe severed debug connection, and manipulation of the boot process.<b> </b></p>"
                        }
                    ]
                }
            ],
            "references": [
                {
                    "url": "https://www.tp-link.com/us/support/download/ec71/v4/#Firmware-Release-Notes",
                    "tags": [
                        "patch"
                    ]
                },
                {
                    "url": "https://www.tp-link.com/us/support/download/ec70/v4/#Firmware-Release-Notes",
                    "tags": [
                        "patch"
                    ]
                },
                {
                    "url": "https://www.tp-link.com/us/support/faq/5324/",
                    "tags": [
                        "vendor-advisory"
                    ]
                }
            ],
            "metrics": [
                {
                    "format": "CVSS",
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "GENERAL"
                        }
                    ],
                    "cvssV4_0": {
                        "attackVector": "PHYSICAL",
                        "attackComplexity": "LOW",
                        "attackRequirements": "PRESENT",
                        "privilegesRequired": "NONE",
                        "userInteraction": "NONE",
                        "vulnConfidentialityImpact": "HIGH",
                        "subConfidentialityImpact": "NONE",
                        "vulnIntegrityImpact": "HIGH",
                        "subIntegrityImpact": "NONE",
                        "vulnAvailabilityImpact": "HIGH",
                        "subAvailabilityImpact": "NONE",
                        "exploitMaturity": "NOT_DEFINED",
                        "Safety": "NOT_DEFINED",
                        "Automatable": "NOT_DEFINED",
                        "Recovery": "NOT_DEFINED",
                        "valueDensity": "NOT_DEFINED",
                        "vulnerabilityResponseEffort": "NOT_DEFINED",
                        "providerUrgency": "NOT_DEFINED",
                        "version": "4.0",
                        "baseSeverity": "MEDIUM",
                        "baseScore": 5.4,
                        "vectorString": "CVSS:4.0/AV:P/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
                    }
                }
            ],
            "credits": [
                {
                    "lang": "en",
                    "value": "Christopher Childress",
                    "type": "finder"
                }
            ],
            "source": {
                "discovery": "UNKNOWN"
            },
            "x_generator": {
                "engine": "Vulnogram 1.0.5"
            }
        },
        "adp": [
            {
                "metrics": [
                    {
                        "other": {
                            "type": "ssvc",
                            "content": {
                                "timestamp": "2026-10-01T21:01:19.841347Z",
                                "id": "CVE-2026-102370",
                                "options": [
                                    {
                                        "Exploitation": "none"
                                    },
                                    {
                                        "Automatable": "no"
                                    },
                                    {
                                        "Technical Impact": "total"
                                    }
                                ],
                                "role": "CISA Coordinator",
                                "version": "2.0.3"
                            }
                        }
                    }
                ],
                "title": "CISA ADP Vulnrichment",
                "providerMetadata": {
                    "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
                    "shortName": "CISA-ADP",
                    "dateUpdated": "2026-10-01T21:01:44.613Z"
                }
            }
        ]
    }
}