An
authenticated format string vulnerability exists in the ONVIF service of Tapo
C110 v2 due to improper handling of user-controlled input. Externally controlled data is interpreted as
a format string, which can be used to manipulate stack memory, including
control flow data such as return addresses.
A remote
authenticated attacker may redirect execution flow to existing internal
functions, triggering an unauthorized factory reset, leading to loss of
configuration, deletion of stored credentials and service disruption.
References
| Link | Resource |
|---|---|
| https://www.tp-link.com/en/support/download/tapo-c110/v2/#Firmware-Release-Notes | Release Notes |
| https://www.tp-link.com/kr/support/download/tapo-c110/v2/#Firmware-Release-Notes | Release Notes |
| https://www.tp-link.com/us/support/download/tapo-c110/v2/#Firmware-Release-Notes | Release Notes |
| https://www.tp-link.com/us/support/faq/5128/ | Vendor Advisory |
Configurations
Configuration 1 (hide)
| AND |
|
History
No history.
Information
Published : 2026-06-11 22:16
Updated : 2026-06-17 11:00
NVD link : CVE-2026-6250
Mitre link : CVE-2026-6250
CVE.ORG link : CVE-2026-6250
JSON object : View
Products Affected
tp-link
- tapo_c110_firmware
- tapo_c110
CWE
CWE-134
Use of Externally-Controlled Format String
