CVE-2026-15314
Received Received - Intake

Buffer Overflow in Tapo P110 v1 Smart Wi-Fi Plug

Vulnerability report for CVE-2026-15314, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-04

Last updated on: 2026-08-04

Assigner: TPLink

Description

Tapo P110 v1 smart Wi-Fi Plug contains an improper boundary validation vulnerability in the handling of authenticated HTTP request bodies due to insufficient input validation before memory copy operations. This may lead to buffer overflow condition, causing the web service process to crash. Successful exploitation may cause the web service process to stop responding or restart, resulting in a denial-of-service condition.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-04
Last Modified
2026-08-04
Generated
2026-08-04
AI Q&A
2026-08-04
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
tp-link tapo_p110 1
tp-link tapo_p110 1.1.4
tp-link tapo_p110 1.1.3

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-120 The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an improper boundary validation issue in the Tapo P110 v1 smart Wi-Fi plug. It occurs due to insufficient input validation before memory copy operations in authenticated HTTP request bodies, leading to potential buffer overflows. This can cause the device's web service process to crash, stop responding, or restart, resulting in a denial-of-service condition.

Detection Guidance

Detecting this vulnerability requires checking the firmware version of the Tapo P110 v1 smart plug. Log in to the device's web interface or use the Tapo app to verify the firmware version. If the version is below V1_1.1.4 Build 260709, the device is vulnerable.

Impact Analysis

Exploitation may cause the smart plug's web service to crash or become unresponsive, disrupting its normal operation. This could lead to loss of remote control over the device, affecting smart home automation and potentially leaving connected appliances in an unusable state until the device restarts or is manually reset.

Compliance Impact

This vulnerability primarily causes a denial-of-service condition by crashing the web service process, which may disrupt device functionality. It does not directly expose or leak sensitive data, but prolonged unavailability could impact systems relying on the smart plug for operations. Compliance impact depends on the specific use case and whether the device is part of a regulated environment.

Mitigation Strategies

Immediately update the firmware of the Tapo P110 v1 to version V1_1.1.4 Build 260709 or later. Download the update from TP-Link's official website and follow the provided instructions to apply it. Ensure the device is connected to the internet during the update process.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-15314. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart