Metrics
Affected Vendors & Products
Tue, 16 Jun 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tp-link tapo C110 Firmware
|
|
| CPEs | cpe:2.3:h:tp-link:tapo_c110:2.0:*:*:*:*:*:*:* cpe:2.3:o:tp-link:tapo_c110_firmware:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Tp-link tapo C110 Firmware
|
|
| Metrics |
cvssV3_1
|
Fri, 12 Jun 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tp-link
Tp-link tapo C110 |
|
| Vendors & Products |
Tp-link
Tp-link tapo C110 |
Fri, 12 Jun 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 11 Jun 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An authenticated format string vulnerability exists in the ONVIF service of Tapo C110 v2 due to improper handling of user-controlled input. Externally controlled data is interpreted as a format string, which can be used to manipulate stack memory, including control flow data such as return addresses. A remote authenticated attacker may redirect execution flow to existing internal functions, triggering an unauthorized factory reset, leading to loss of configuration, deletion of stored credentials and service disruption. | |
| Title | Authenticated Format String Injection on TP-Link Tapo C110 | |
| Weaknesses | CWE-134 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: TPLink
Published:
Updated: 2026-06-12T15:41:58.140Z
Reserved: 2026-04-13T18:44:25.412Z
Link: CVE-2026-6250
Updated: 2026-06-12T15:41:54.638Z
Status : Analyzed
Published: 2026-06-11T22:16:57.870
Modified: 2026-06-16T14:19:23.487
Link: CVE-2026-6250
No data.
OpenCVE Enrichment
Updated: 2026-06-12T20:21:33Z