CVE-2026-15314

HIGH CVSS 4.0: 7.1 EPSS 0.50%
Updated Aug 07, 2026
TP-Link
Parameter Value
CVSS 7.1 (HIGH)
Affected Versions before 1.1.4
Fixed In 1.1.4
Type CWE-120 (Buffer Copy without Checking Size)
Vendor TP-Link
Public PoC No

Tapo P110 v1 smart Wi-Fi Plug contains an improper boundary validation vulnerability in the handling of authenticated HTTP request bodies due to insufficient input validation before memory copy operations. This may lead to buffer overflow condition, causing the web service process to crash. Successful exploitation may cause the web service process to stop responding or restart, resulting in a denial-of-service condition.

Attack Parameters

Attack Vector
Adjacent
Requires local network access
Attack Complexity
Low
Easy to exploit
Attack Requirements
None
No additional conditions
Privileges Required
None
No privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
None
No data leak
Integrity
None
No data modification
Availability
High
Complete denial of service

CVSS Vector v4.0

Vulnerable Products 2

Configuration From (including) Up to (excluding)
Tp-Link Tapo_P110_Firmware
cpe:2.3:o:tp-link:tapo_p110_firmware:*:*:*:*:*:*:*:*
1.1.4
Tp-Link Tapo_P110
cpe:2.3:h:tp-link:tapo_p110:1.0:*:*:*:*:*:*:*