CVE-2026-15314 HIGH

CVE-2026-15314: Authenticated Denial-of-Service Vulnerability in TP-Link Tapo P110

Vendor Tp-Link Systems Inc.
Product P110 v1
Weakness CWE-120
Published August 4, 2026
Last update August 5, 2026

CVSS base score

7.1/10
Attack vector Adjacent
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

What the vulnerability does

01Description

Tapo P110 v1 smart Wi-Fi Plug contains an improper boundary validation vulnerability in the handling of authenticated HTTP request bodies due to insufficient input validation before memory copy operations. This may lead to buffer overflow condition, causing the web service process to crash. Successful exploitation may cause the web service process to stop responding or restart, resulting in a denial-of-service condition.

Key dates

02Disclosure timeline

August 4, 2026 CVE published
August 5, 2026 Record updated