CVE-2026-15314

Summary

Tapo P110 v1 smart Wi-Fi Plug contains an improper boundary validation vulnerability in the handling of authenticated HTTP request bodies due to insufficient input validation before memory copy operations. This may lead to buffer overflow condition, causing the web service process to crash.

Successful exploitation may cause the web service process to stop responding or restart, resulting in a denial-of-service condition.

Affected Software

VendorProductVersion RangeStatus
TP-Link Systems Inc.P110 v10 < V1_1.1.4 Build 260709affected

Weaknesses

  • CWE-120: CWE-120 Buffer Copy without Checking Size of Input

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References