{"document":{"category":"csaf_vex","csaf_version":"2.0","title":"CVE-2026-6250: Authenticated Format String Injection on TP-Link Tapo C110","publisher":{"category":"vendor","name":"HarborGuard Database","namespace":"https://database.harborguard.co"},"tracking":{"id":"CVE-2026-6250","status":"final","version":"1","initial_release_date":"2026-06-11T20:46:09.672Z","current_release_date":"2026-06-12T15:41:58.140Z","revision_history":[{"date":"2026-06-11T20:46:09.672Z","number":"1","summary":"Initial machine-readable export from HarborGuard."}]},"distribution":{"tlp":{"label":"WHITE"},"text":"Public CVE data; freely redistributable."},"notes":[{"category":"description","text":"An\nauthenticated format string vulnerability exists in the ONVIF service of Tapo\nC110 v2 due to improper handling of user-controlled input.  Externally controlled data is interpreted as\na format string, which can be used to manipulate stack memory, including\ncontrol flow data such as return addresses.\n\n\n\n\n\nA remote\nauthenticated attacker may redirect execution flow to existing internal\nfunctions, triggering an unauthorized factory reset, leading to loss of\nconfiguration, deletion of stored credentials and service disruption.","title":"CVE description"}],"references":[{"category":"self","summary":"CVE-2026-6250 on HarborGuard Database","url":"https://database.harborguard.co/cve/CVE-2026-6250"},{"category":"external","summary":"CVE Record","url":"https://www.cve.org/CVERecord?id=CVE-2026-6250"},{"category":"external","summary":"tp-link.com","url":"https://www.tp-link.com/us/support/download/tapo-c110/v2/#Firmware-Release-Notes"},{"category":"external","summary":"tp-link.com","url":"https://www.tp-link.com/en/support/download/tapo-c110/v2/#Firmware-Release-Notes"},{"category":"external","summary":"tp-link.com","url":"https://www.tp-link.com/kr/support/download/tapo-c110/v2/#Firmware-Release-Notes"},{"category":"external","summary":"tp-link.com","url":"https://www.tp-link.com/us/support/faq/5128/"}]},"product_tree":{"branches":[{"category":"vendor","name":"TP-Link Systems Inc.","branches":[{"category":"product_name","name":"Tapo C110 v2","branches":[{"category":"product_version_range","name":"<1.5.4 Build 260428","product":{"name":"TP-Link Systems Inc. Tapo C110 v2 <1.5.4 Build 260428","product_id":"CSAFPID-1","product_identification_helper":{"cpe":"cpe:2.3:a:tp-link_systems_inc.:tapo_c110_v2:*:*:*:*:*:*:*:*"}}}]}]}]},"vulnerabilities":[{"cve":"CVE-2026-6250","title":"Authenticated Format String Injection on TP-Link Tapo C110","notes":[{"category":"description","text":"An\nauthenticated format string vulnerability exists in the ONVIF service of Tapo\nC110 v2 due to improper handling of user-controlled input.  Externally controlled data is interpreted as\na format string, which can be used to manipulate stack memory, including\ncontrol flow data such as return addresses.\n\n\n\n\n\nA remote\nauthenticated attacker may redirect execution flow to existing internal\nfunctions, triggering an unauthorized factory reset, leading to loss of\nconfiguration, deletion of stored credentials and service disruption.","title":"CVE description"}],"product_status":{"known_affected":["CSAFPID-1"]},"scores":[{"cvss_v4":{"version":"4.0","vectorString":"CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N","baseScore":7,"baseSeverity":"HIGH"},"products":["CSAFPID-1"]}],"remediations":[{"category":"vendor_fix","details":"Update to a fixed version: 1.5.4 Build 260428.","product_ids":["CSAFPID-1"],"url":"https://www.tp-link.com/us/support/download/tapo-c110/v2/#Firmware-Release-Notes"}]}]}