7.5
CVE-2026-15314
- EPSS 0.5%
- Veröffentlicht 04.08.2026 16:59:45
- Zuletzt bearbeitet 07.08.2026 20:45:30
- Erkennungen
Authenticated Denial-of-Service Vulnerability in TP-Link Tapo P110
Tapo P110 v1 smart Wi-Fi Plug contains an improper boundary validation vulnerability in the handling of authenticated HTTP request bodies due to insufficient input validation before memory copy operations. This may lead to buffer overflow condition, causing the web service process to crash. Successful exploitation may cause the web service process to stop responding or restart, resulting in a denial-of-service condition.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Tp-link ≫ Tapo P110 Firmware Version < 1.1.4
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.5% | 0.401 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
| f23511db-6c3e-4e32-a477-6aa17d310630 | 7.1 | 0 | 0 |
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.
https://www.tp-link.com/us/support/download/tapo-p110/v1/#Firmware-Release-Notes
https://www.tp-link.com/en/support/download/tapo-p110/v1/#Firmware-Release-Notes
https://www.tp-link.com/us/support/faq/5220/