CVE-2026-6250: TP-Link Tapo c110 Firmware
High severity, CVSS 8.1. EPSS: 0.9% chance of exploitation in the next 30 days.
An authenticated format string vulnerability exists in the ONVIF service of Tapo C110 v2 due to improper handling of user-controlled input. Externally controlled data is interpreted as a format string, which can be used to manipulate stack memory, including control flow data such as return addresses. A remote authenticated attacker may redirect execution flow to existing internal functions, triggering an unauthorized factory reset, leading to loss of configuration, deletion of stored credentials and service disruption.
Affected products
- TP-Link Tapo c110 Firmware: before 1.5.4 (fixed in 1.5.4)
Published 2026-06-11. Last modified 2026-06-17.