Debug Interface Vulnerability in Kasa Smart Plug by TP-Link
CVE-2026-102370

5.4MEDIUM

What is CVE-2026-102370?

The Kasa EC70 v4 and EC71 v4 devices have a vulnerability that fails to appropriately disable their debug interface and lock the bootloader, which can be exploited if an attacker gains physical access. This condition allows the attacker to restore a severed debug connection and manipulate the device's boot parameters, potentially providing unauthorized root-level access during startup. As a result, sensitive information and functionality could be compromised. To exploit this vulnerability, the attacker would need to disassemble the device and navigate through specific initialization paths.

Affected Version(s)

Kasa EC70 V4 0 < 2.4.3 Build 20260902 rel.4511

Kasa EC71 V4 0 < 2.4.3 Build 20260902 rel.4511

References

CVSS V4

Score:
5.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Christopher Childress
.