CVE-2026-6250

An authenticated format string vulnerability exists in the ONVIF service of Tapo C110 v2 due to improper handling of user-controlled input.  Externally controlled data is interpreted as a format string, which can be used to manipulate stack memory, including control flow data such as return addresses. A remote authenticated attacker may redirect execution flow to existing internal functions, triggering an unauthorized factory reset, leading to loss of configuration, deletion of stored credentials and service disruption.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:tp-link:tapo_c110_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:tapo_c110:2.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-06-11 22:16

Updated : 2026-06-17 11:00


NVD link : CVE-2026-6250

Mitre link : CVE-2026-6250

CVE.ORG link : CVE-2026-6250


JSON object : View

Products Affected

tp-link

  • tapo_c110_firmware
  • tapo_c110
CWE
CWE-134

Use of Externally-Controlled Format String