Description
Tapo P110 v1
smart Wi-Fi Plug contains an improper boundary validation vulnerability in the
handling of authenticated HTTP request bodies due to insufficient input
validation before memory copy operations. This may lead to buffer overflow condition,
causing the web service process to crash.





Successful exploitation
may cause the web service process to stop responding or restart, resulting in a
denial-of-service condition.
Published: 2026-08-04
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Tapo P110 v1 contains a buffer overflow flaw caused by inadequate validation of boundaries when processing authenticated HTTP requests, allowing an attacker to overwrite memory during copy operations and crash its web service process. The resulting crash either stops the process or forces a restart, producing a denial‑of‑service condition for the device’s management interface.

Affected Systems

The vulnerability affects TP‑Link Tapo P110 v1. No other product or version is listed as impacted.

Risk and Exploitability

The CVSS score of 7.1 indicates a high‑severity flaw. Exploitation requires an authenticated session to the device’s web interface, so an attacker must first gain legitimate credentials or access a local network where the plug is reachable. The EPSS score is unavailable and the vulnerability is not in the CISA KEV catalog, suggesting that widespread exploitation has not yet been observed. Nonetheless, the impact is confined to the targeted plug, but repeated crashes can trigger service‑degradation incidents in a smart‑home or small‑office environment.

Generated by OpenCVE AI on August 4, 2026 at 19:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the device firmware to the latest version that includes the correction for the boundary‑validation bug.
  • Restrict access to the plug’s web interface by placing it on a secured network segment or by enabling only VPN or firewall rules that limit access to trusted IP ranges.
  • Continuously monitor the plug for unexpected restarts or service‑unavailable states and consider replacing the device if a vendor patch is not forthcoming.

Generated by OpenCVE AI on August 4, 2026 at 19:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Tp-link
Tp-link p110 V1
Vendors & Products Tp-link
Tp-link p110 V1

Tue, 04 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 04 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Description Tapo P110 v1 smart Wi-Fi Plug contains an improper boundary validation vulnerability in the handling of authenticated HTTP request bodies due to insufficient input validation before memory copy operations. This may lead to buffer overflow condition, causing the web service process to crash. Successful exploitation may cause the web service process to stop responding or restart, resulting in a denial-of-service condition.
Title Authenticated Denial-of-Service Vulnerability in TP-Link Tapo P110
Weaknesses CWE-120
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Tp-link P110 V1 Tapo P110 Tapo P110 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: TPLink

Published:

Updated: 2026-08-05T17:47:43.539Z

Reserved: 2026-07-09T17:54:06.348Z

Link: CVE-2026-15314

cve-icon Vulnrichment

Updated: 2026-08-04T17:24:07.154Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-04T17:16:46.313

Modified: 2026-08-07T20:45:30.937

Link: CVE-2026-15314

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T10:19:42Z

Weaknesses
  • CWE-120

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')