Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-6250

Опубликовано: 11 июн. 2026
Источник: nvd
CVSS3: 8.1
EPSS Низкий

Описание

An authenticated format string vulnerability exists in the ONVIF service of Tapo C110 v2 due to improper handling of user-controlled input.  Externally controlled data is interpreted as a format string, which can be used to manipulate stack memory, including control flow data such as return addresses.

A remote authenticated attacker may redirect execution flow to existing internal functions, triggering an unauthorized factory reset, leading to loss of configuration, deletion of stored credentials and service disruption.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:tp-link:tapo_c110_firmware:*:*:*:*:*:*:*:*
Версия до 1.5.4 (исключая)
cpe:2.3:h:tp-link:tapo_c110:2.0:*:*:*:*:*:*:*

EPSS

Процентиль: 38%
0.00463
Низкий

8.1 High

CVSS3

Дефекты

CWE-134
CWE-134

Связанные уязвимости

CVSS3: 8.1
github
2 месяца назад

An authenticated format string vulnerability exists in the ONVIF service of Tapo C110 v2 due to improper handling of user-controlled input.  Externally controlled data is interpreted as a format string, which can be used to manipulate stack memory, including control flow data such as return addresses. A remote authenticated attacker may redirect execution flow to existing internal functions, triggering an unauthorized factory reset, leading to loss of configuration, deletion of stored credentials and service disruption.

EPSS

Процентиль: 38%
0.00463
Низкий

8.1 High

CVSS3

Дефекты

CWE-134
CWE-134