{"@context":"https://openvex.dev/ns/v0.2.0","@id":"https://database.harborguard.co/cve/CVE-2026-6250/vex.json","author":"HarborGuard Database","role":"Document Creator","timestamp":"2026-06-12T15:41:58.140Z","version":1,"tooling":"HarborGuard Database (https://database.harborguard.co)","statements":[{"vulnerability":{"name":"CVE-2026-6250","@id":"https://www.cve.org/CVERecord?id=CVE-2026-6250","description":"An\nauthenticated format string vulnerability exists in the ONVIF service of Tapo\nC110 v2 due to improper handling of user-controlled input.  Externally controlled data is interpreted as\na format string, which can be used to manipulate stack memory, including\ncontrol flow data such as return addresses.\n\n\n\n\n\nA remote\nauthenticated attacker may redirect execution flow to existing internal\nfunctions, triggering an unauthorized factory reset, leading to loss of\nconfiguration, deletion of stored crede"},"products":[{"@id":"cpe:2.3:a:tp-link_systems_inc.:tapo_c110_v2:*:*:*:*:*:*:*:*","identifiers":{"cpe23":"cpe:2.3:a:tp-link_systems_inc.:tapo_c110_v2:*:*:*:*:*:*:*:*"}}],"status":"affected","action_statement":"Update to a fixed version: 1.5.4 Build 260428.","timestamp":"2026-06-12T15:41:58.140Z"}]}