Tapo P110 v1
smart Wi-Fi Plug contains an improper boundary validation vulnerability in the
handling of authenticated HTTP request bodies due to insufficient input
validation before memory copy operations. This may lead to buffer overflow condition,
causing the web service process to crash.
Successful exploitation
may cause the web service process to stop responding or restart, resulting in a
denial-of-service condition.
References
| Link | Resource |
|---|---|
| https://www.tp-link.com/en/support/download/tapo-p110/v1/#Firmware-Release-Notes | Release Notes |
| https://www.tp-link.com/us/support/download/tapo-p110/v1/#Firmware-Release-Notes | Release Notes |
| https://www.tp-link.com/us/support/faq/5220/ | Vendor Advisory |
Configurations
Configuration 1 (hide)
| AND |
|
History
07 Aug 2026, 20:45
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Tp-link
Tp-link tapo P110 Tp-link tapo P110 Firmware |
|
| CPE | cpe:2.3:o:tp-link:tapo_p110_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:tp-link:tapo_p110:1.0:*:*:*:*:*:*:* |
|
| References | () https://www.tp-link.com/en/support/download/tapo-p110/v1/#Firmware-Release-Notes - Release Notes | |
| References | () https://www.tp-link.com/us/support/download/tapo-p110/v1/#Firmware-Release-Notes - Release Notes | |
| References | () https://www.tp-link.com/us/support/faq/5220/ - Vendor Advisory | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
04 Aug 2026, 17:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-08-04 17:16
Updated : 2026-08-07 20:45
NVD link : CVE-2026-15314
Mitre link : CVE-2026-15314
CVE.ORG link : CVE-2026-15314
JSON object : View
Products Affected
tp-link
- tapo_p110
- tapo_p110_firmware
CWE
CWE-120
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
