CVE-2026-6250 Details
Description
An authenticated format string vulnerability exists in the ONVIF service of Tapo C110 v2 due to improper handling of user-controlled input. Externally controlled data is interpreted as a format string, which can be used to manipulate stack memory, including control flow data such as return addresses. A remote authenticated attacker may redirect execution flow to existing internal functions, triggering an unauthorized factory reset, leading to loss of configuration, deletion of stored credentials and service disruption.
A format string vulnerability has been identified in the ONVIF service of the TP-Link Tapo C110 camera, version 2, prior to 1.5.4 Build 260428. This vulnerability allows an authenticated attacker to manipulate stack memory by exploiting improper handling of user-controlled input. The exploitation can redirect execution flow to internal functions, potentially triggering an unauthorized factory reset. Such an action would result in the loss of configuration, deletion of stored credentials, and disruption of service.
Users are advised to update the device to the latest firmware version. The updated version can be downloaded from the TP-Link website, with specific links available for the US, English, and Korean versions.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 12, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.tp-link.com/en/support/download/tapo-c110/v2/#Firmware-Release-Notes | TPLink | Release Notes |
| https://www.tp-link.com/kr/support/download/tapo-c110/v2/#Firmware-Release-Notes | TPLink | Release Notes |
| https://www.tp-link.com/us/support/download/tapo-c110/v2/#Firmware-Release-Notes | TPLink | Release Notes |
| https://www.tp-link.com/us/support/faq/5128/ | TPLink | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-134 | Use of Externally-Controlled Format String | [email protected] |
| CWE-134 | Use of Externally-Controlled Format String | TPLink |
Affected Products
| Product | Versions |
|---|---|
| tp-link tapo c110 firmware | < 1.5.4 |
CPE
Remediation
| |
| tp-link tapo c110 | 2.0 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | TPLink |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 16, 2026 | Initial Analysis | [email protected] |
| Jun 11, 2026 | New CVE Received | TPLink |