CVE-2026-6250

Severity CVSS v4.0:
HIGH
Type:
CWE-134 Format String Vulnerability
Publication date:
11/06/2026
Last modified:
16/06/2026

Description

An<br /> authenticated format string vulnerability exists in the ONVIF service of Tapo<br /> C110 v2 due to improper handling of user-controlled input.  Externally controlled data is interpreted as<br /> a format string, which can be used to manipulate stack memory, including<br /> control flow data such as return addresses.<br /> <br /> <br /> <br /> <br /> <br /> A remote<br /> authenticated attacker may redirect execution flow to existing internal<br /> functions, triggering an unauthorized factory reset, leading to loss of<br /> configuration, deletion of stored credentials and service disruption.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:tp-link:tapo_c110_firmware:*:*:*:*:*:*:*:* 1.5.4 (excluding)
cpe:2.3:h:tp-link:tapo_c110:2.0:*:*:*:*:*:*:*