CVE-2026-15314

Severity CVSS v4.0:
HIGH
Type:
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Publication date:
04/08/2026
Last modified:
07/08/2026

Description

Tapo P110 v1<br /> smart Wi-Fi Plug contains an improper boundary validation vulnerability in the<br /> handling of authenticated HTTP request bodies due to insufficient input<br /> validation before memory copy operations. This may lead to buffer overflow condition,<br /> causing the web service process to crash.<br /> <br /> <br /> <br /> <br /> <br /> Successful exploitation<br /> may cause the web service process to stop responding or restart, resulting in a<br /> denial-of-service condition.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:tp-link:tapo_p110_firmware:*:*:*:*:*:*:*:* 1.1.4 (excluding)
cpe:2.3:h:tp-link:tapo_p110:1.0:*:*:*:*:*:*:*