CVE-2026-6250
An authenticated format string vulnerability exists in the ONVIF service of Tapo C110 v2 due to improper handling of user-controlled input
Published: 2026-06-11 · Last updated: 2026-06-12
Severity and scoring
- CWE
- CWE-134
Description
An authenticated format string vulnerability exists in the ONVIF service of Tapo C110 v2 due to improper handling of user-controlled input. Externally controlled data is interpreted as a format string, which can be used to manipulate stack memory, including control flow data such as return addresses. A remote authenticated attacker may redirect execution flow to existing internal functions, triggering an unauthorized factory reset, leading to loss of configuration, deletion of stored credentials and service disruption.
Source: NVD
References
- [NVD]https://nvd.nist.gov/vuln/detail/CVE-2026-6250
- [Other]https://www.tp-link.com/en/support/download/tapo-c110/v2/#Firmware-Release-Notes
- [Other]https://www.tp-link.com/kr/support/download/tapo-c110/v2/#Firmware-Release-Notes
- [Other]https://www.tp-link.com/us/support/download/tapo-c110/v2/#Firmware-Release-Notes
- [Other]https://www.tp-link.com/us/support/faq/5128/
Related CVEs
Same CWE
- CVE-2026-12174 — A security vulnerability has been detected in D-Link DCS-935L 1.10.01 (8.8 HIGH)
- CVE-2026-6242 — An authenticated format string vulnerability exists in the ONVIF Subscribe service in Tapo C520WS v2 due to improper handling of external...
- CVE-2026-6241 — An authenticated format string vulnerability is present in the ONVIF AddScopes in Tapo C520WS v2, where user-controlled input is improper...
- CVE-2026-50211 — Leftover engineering diagnostics and factory-level diagnostic software remain exposed on retail builds, giving malicious apps write privi... (9.8 CRITICAL)
- CVE-2026-7835 — A format string argument mismatch in Netatalk 3.0.3 through 4.4.2 allows a remote authenticated attacker to cause a minor denial of servi... (3.1 LOW)