Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-6250

Gravedad CVSS v4.0:
ALTA
Tipo:
CWE-134 Utilización de formatos de cadenas de control externo
Fecha de publicación:
11/06/2026
Última modificación:
11/06/2026

Descripción

*** Pendiente de traducción *** An<br /> authenticated format string vulnerability exists in the ONVIF service of Tapo<br /> C110 v2 due to improper handling of user-controlled input.  Externally controlled data is interpreted as<br /> a format string, which can be used to manipulate stack memory, including<br /> control flow data such as return addresses.<br /> <br /> <br /> <br /> <br /> <br /> A remote<br /> authenticated attacker may redirect execution flow to existing internal<br /> functions, triggering an unauthorized factory reset, leading to loss of<br /> configuration, deletion of stored credentials and service disruption.