Restoring severed UART traces on a Kasa EC70 or EC71 exposes a root shell at boot.
TP-Link Kasa EC70 and EC71, embedded Wi-Fi home security cameras.
The path requires physical possession, disassembly, restoration of the debug traces and interaction with the boot process.
Detail and 1 source
The production debug interface remains logically enabled and the bootloader remains unlocked despite the severed traces.
An attacker can interrupt boot, change boot parameters and obtain an unauthenticated root shell.
This defeats invasive-tamper resistance rather than a remote boundary; TP-Link published fixed firmware, but the fix was not read for this brief.