Impact
Tapo P110 v1 contains a buffer overflow flaw caused by inadequate validation of boundaries when processing authenticated HTTP requests, allowing an attacker to overwrite memory during copy operations and crash its web service process. The resulting crash either stops the process or forces a restart, producing a denial‑of‑service condition for the device’s management interface.
Affected Systems
The vulnerability affects TP‑Link Tapo P110 v1. No other product or version is listed as impacted.
Risk and Exploitability
The CVSS score of 7.1 indicates a high‑severity flaw. Exploitation requires an authenticated session to the device’s web interface, so an attacker must first gain legitimate credentials or access a local network where the plug is reachable. The EPSS score is unavailable and the vulnerability is not in the CISA KEV catalog, suggesting that widespread exploitation has not yet been observed. Nonetheless, the impact is confined to the targeted plug, but repeated crashes can trigger service‑degradation incidents in a smart‑home or small‑office environment.
OpenCVE Enrichment