CVE-2026-15314

Tapo P110 v1 smart Wi-Fi Plug contains an improper boundary validation vulnerability in the handling of authenticated HTTP request bodies due to insufficient input validation before memory copy operations. This may lead to buffer overflow condition, causing the web service process to crash. Successful exploitation may cause the web service process to stop responding or restart, resulting in a denial-of-service condition.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:tp-link:tapo_p110_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:tapo_p110:1.0:*:*:*:*:*:*:*

History

07 Aug 2026, 20:45

Type Values Removed Values Added
First Time Tp-link
Tp-link tapo P110
Tp-link tapo P110 Firmware
CPE cpe:2.3:o:tp-link:tapo_p110_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:tapo_p110:1.0:*:*:*:*:*:*:*
References () https://www.tp-link.com/en/support/download/tapo-p110/v1/#Firmware-Release-Notes - () https://www.tp-link.com/en/support/download/tapo-p110/v1/#Firmware-Release-Notes - Release Notes
References () https://www.tp-link.com/us/support/download/tapo-p110/v1/#Firmware-Release-Notes - () https://www.tp-link.com/us/support/download/tapo-p110/v1/#Firmware-Release-Notes - Release Notes
References () https://www.tp-link.com/us/support/faq/5220/ - () https://www.tp-link.com/us/support/faq/5220/ - Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

04 Aug 2026, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-08-04 17:16

Updated : 2026-08-07 20:45


NVD link : CVE-2026-15314

Mitre link : CVE-2026-15314

CVE.ORG link : CVE-2026-15314


JSON object : View

Products Affected

tp-link

  • tapo_p110
  • tapo_p110_firmware
CWE
CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')