Debug Interface Vulnerability in Kasa Smart Plug by TP-Link
CVE-2026-102370
5.4MEDIUM
Key Information:
- Vendor
Tp-link Systems Inc.
- Status
- Vendor
- CVE Published:
- 1 October 2026
What is CVE-2026-102370?
The Kasa EC70 v4 and EC71 v4 devices have a vulnerability that fails to appropriately disable their debug interface and lock the bootloader, which can be exploited if an attacker gains physical access. This condition allows the attacker to restore a severed debug connection and manipulate the device's boot parameters, potentially providing unauthorized root-level access during startup. As a result, sensitive information and functionality could be compromised. To exploit this vulnerability, the attacker would need to disassemble the device and navigate through specific initialization paths.
Affected Version(s)
Kasa EC70 V4 0 < 2.4.3 Build 20260902 rel.4511
Kasa EC71 V4 0 < 2.4.3 Build 20260902 rel.4511
