CVE-2026-6250

An authenticated format string vulnerability exists in the ONVIF service of Tapo C110 v2 due to improper handling of user-controlled input.  Externally controlled data is interpreted as a format string, which can be used to manipulate stack memory, including control flow data such as return addresses. A remote authenticated attacker may redirect execution flow to existing internal functions, triggering an unauthorized factory reset, leading to loss of configuration, deletion of stored credentials and service disruption.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:tp-link:tapo_c110_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:tapo_c110:2.0:*:*:*:*:*:*:*

History

16 Jun 2026, 14:19

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.1
First Time Tp-link
Tp-link tapo C110 Firmware
Tp-link tapo C110
CPE cpe:2.3:h:tp-link:tapo_c110:2.0:*:*:*:*:*:*:*
cpe:2.3:o:tp-link:tapo_c110_firmware:*:*:*:*:*:*:*:*
References () https://www.tp-link.com/en/support/download/tapo-c110/v2/#Firmware-Release-Notes - () https://www.tp-link.com/en/support/download/tapo-c110/v2/#Firmware-Release-Notes - Release Notes
References () https://www.tp-link.com/kr/support/download/tapo-c110/v2/#Firmware-Release-Notes - () https://www.tp-link.com/kr/support/download/tapo-c110/v2/#Firmware-Release-Notes - Release Notes
References () https://www.tp-link.com/us/support/download/tapo-c110/v2/#Firmware-Release-Notes - () https://www.tp-link.com/us/support/download/tapo-c110/v2/#Firmware-Release-Notes - Release Notes
References () https://www.tp-link.com/us/support/faq/5128/ - () https://www.tp-link.com/us/support/faq/5128/ - Vendor Advisory

11 Jun 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-11 22:16

Updated : 2026-06-16 14:19


NVD link : CVE-2026-6250

Mitre link : CVE-2026-6250

CVE.ORG link : CVE-2026-6250


JSON object : View

Products Affected

tp-link

  • tapo_c110_firmware
  • tapo_c110
CWE
CWE-134

Use of Externally-Controlled Format String