An
authenticated format string vulnerability exists in the ONVIF service of Tapo
C110 v2 due to improper handling of user-controlled input. Externally controlled data is interpreted as
a format string, which can be used to manipulate stack memory, including
control flow data such as return addresses.
A remote
authenticated attacker may redirect execution flow to existing internal
functions, triggering an unauthorized factory reset, leading to loss of
configuration, deletion of stored credentials and service disruption.
References
| Link | Resource |
|---|---|
| https://www.tp-link.com/en/support/download/tapo-c110/v2/#Firmware-Release-Notes | Release Notes |
| https://www.tp-link.com/kr/support/download/tapo-c110/v2/#Firmware-Release-Notes | Release Notes |
| https://www.tp-link.com/us/support/download/tapo-c110/v2/#Firmware-Release-Notes | Release Notes |
| https://www.tp-link.com/us/support/faq/5128/ | Vendor Advisory |
Configurations
Configuration 1 (hide)
| AND |
|
History
16 Jun 2026, 14:19
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.1 |
| First Time |
Tp-link
Tp-link tapo C110 Firmware Tp-link tapo C110 |
|
| CPE | cpe:2.3:h:tp-link:tapo_c110:2.0:*:*:*:*:*:*:* cpe:2.3:o:tp-link:tapo_c110_firmware:*:*:*:*:*:*:*:* |
|
| References | () https://www.tp-link.com/en/support/download/tapo-c110/v2/#Firmware-Release-Notes - Release Notes | |
| References | () https://www.tp-link.com/kr/support/download/tapo-c110/v2/#Firmware-Release-Notes - Release Notes | |
| References | () https://www.tp-link.com/us/support/download/tapo-c110/v2/#Firmware-Release-Notes - Release Notes | |
| References | () https://www.tp-link.com/us/support/faq/5128/ - Vendor Advisory |
11 Jun 2026, 22:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-11 22:16
Updated : 2026-06-16 14:19
NVD link : CVE-2026-6250
Mitre link : CVE-2026-6250
CVE.ORG link : CVE-2026-6250
JSON object : View
Products Affected
tp-link
- tapo_c110_firmware
- tapo_c110
CWE
CWE-134
Use of Externally-Controlled Format String
