Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4gmj-9m2m-6h5f

Опубликовано: 12 июн. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 7
CVSS3: 8.1

Описание

An authenticated format string vulnerability exists in the ONVIF service of Tapo C110 v2 due to improper handling of user-controlled input.  Externally controlled data is interpreted as a format string, which can be used to manipulate stack memory, including control flow data such as return addresses.

A remote authenticated attacker may redirect execution flow to existing internal functions, triggering an unauthorized factory reset, leading to loss of configuration, deletion of stored credentials and service disruption.

An authenticated format string vulnerability exists in the ONVIF service of Tapo C110 v2 due to improper handling of user-controlled input.  Externally controlled data is interpreted as a format string, which can be used to manipulate stack memory, including control flow data such as return addresses.

A remote authenticated attacker may redirect execution flow to existing internal functions, triggering an unauthorized factory reset, leading to loss of configuration, deletion of stored credentials and service disruption.

EPSS

Процентиль: 38%
0.00463
Низкий

7 High

CVSS4

8.1 High

CVSS3

Дефекты

CWE-134

Связанные уязвимости

CVSS3: 8.1
nvd
2 месяца назад

An authenticated format string vulnerability exists in the ONVIF service of Tapo C110 v2 due to improper handling of user-controlled input.  Externally controlled data is interpreted as a format string, which can be used to manipulate stack memory, including control flow data such as return addresses. A remote authenticated attacker may redirect execution flow to existing internal functions, triggering an unauthorized factory reset, leading to loss of configuration, deletion of stored credentials and service disruption.

EPSS

Процентиль: 38%
0.00463
Низкий

7 High

CVSS4

8.1 High

CVSS3

Дефекты

CWE-134