Skip to finding
important · Physical

Restoring severed UART traces on a Kasa EC70 or EC71 exposes a root shell at boot.

Affects

TP-Link Kasa EC70 and EC71, embedded Wi-Fi home security cameras.

The path requires physical possession, disassembly, restoration of the debug traces and interaction with the boot process.

Detail and 1 source

The production debug interface remains logically enabled and the bootloader remains unlocked despite the severed traces.

An attacker can interrupt boot, change boot parameters and obtain an unauthenticated root shell.

This defeats invasive-tamper resistance rather than a remote boundary; TP-Link published fixed firmware, but the fix was not read for this brief.

Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Saturday, October 3, 2026