CVE-2026-102370
CVE-2026-102370 is a medium-severity vulnerability with a CVSS 4.0 base score of 5.4. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-1191.
Key facts
- Severity: Medium (CVSS 4.0 base score 5.4)
- EPSS exploit prediction: 0% (7th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-1191
- Published:
- Last modified:
Description
Kasa EC70 v4 and EC71 v4 do not logically disable the production debug interface at the firmware or chip level and do not lock the bootloader. Although the debug traces are physically severed during manufacturing, an attacker with physical access can restore the connection, interrupt the boot process, and manipulate boot parameters to enter a non-standard initialization path that exposes an unauthenticated root shell during startup. Successful exploitation may allow an attacker with physical access to obtain root-level command access during device startup, resulting in loss of confidentiality, integrity, and availability for the affected device. Exploitation requires device disassembly, restoration of the severed debug connection, and manipulation of the boot process.
Frequently asked questions
- What is CVE-2026-102370?
- Kasa EC70 v4 and EC71 v4 do not logically disable the production debug interface at the firmware or chip level and do not lock the bootloader. Although the debug traces are physically severed during manufacturing, an attacker with physical access can restore the connection, interrupt the boot process, and manipulate boot parameters to enter a non-standard initialization path that exposes an unauthenticated root shell during startup. Successful exploitation may allow an attacker with physical access to obtain root-level command access during device startup, resulting in loss of confidentiality, integrity, and availability for the affected device. Exploitation requires device disassembly, restoration of the severed debug connection, and manipulation of the boot process.
- How severe is CVE-2026-102370?
- CVE-2026-102370 has a CVSS 4.0 base score of 5.4, rated medium severity.
- Is CVE-2026-102370 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (7th percentile), an estimate of the probability of exploitation in the next 30 days.
- How do I fix CVE-2026-102370?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2026-102370 published?
- CVE-2026-102370 was published on 2026-10-01 and last updated on 2026-10-02.
References
- https://www.tp-link.com/us/support/download/ec70/v4/#Firmware-Release-Notes
- https://www.tp-link.com/us/support/download/ec71/v4/#Firmware-Release-Notes
- https://www.tp-link.com/us/support/faq/5324/
Other CWE-1191 vulnerabilities
- CVE-2026-15203 — Critical (CVSS 9.3): Improper access control in debug and engineering interfaces in Danfoss iC7-Automation SP, iC7-Marine, and iC7-Hybrid…
- CVE-2024-48970 — Critical (CVSS 9.3): The ventilator's microcontroller lacks memory protection. An attacker could connect to the internal JTAG interface and…
- CVE-2025-52533 — High (CVSS 8.7): Improper Access Control in an on-chip debug interface could allow a privileged attacker to enable a debug interface and…
- CVE-2025-9709 — High (CVSS 8.6): On-Chip Debug and Test Interface With Improper Access Control and Improper Protection against Electromagnetic Fault…
- CVE-2024-41692 — High (CVSS 8.6): This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to presence of root terminal access on a serial…
- CVE-2025-65821 — High (CVSS 7.5): As UART download mode is still enabled on the ESP32 chip on which the firmware runs, an adversary can dump the flash…