CVE Feed

    Dashboard / CVE / CVE-2026-6250

    CVE-2026-6250

    An authenticated format string vulnerability exists in the ONVIF service of Tapo C110 v2 due to improper handling of user-controlled input.  Externally controlled data is interpreted as a format string, which can be used to manipulate stack memory, including control flow data such as return addresses. A remote authenticated attacker may redirect execution flow to existing internal functions, triggering an unauthorized factory reset, leading to loss of configuration, deletion of stored credentials and service disruption.

    Published:Jun 11, 2026
    Last Modified:Jun 16, 2026
    EPS:Jun 11, 2026
    EPSS Score:0.0021
    CVSS Score:8.1

    Affected Products

    Vendor
    Tp-link
    Product
    Tapo C110
    Vendor
    Tp-link
    Product
    Tapo C110 Firmware

    Exploits

    No exploit reference

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High