{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2026-15314", "assignerOrgId": "f23511db-6c3e-4e32-a477-6aa17d310630", "state": "PUBLISHED", "assignerShortName": "TPLink", "dateReserved": "2026-07-09T17:54:06.348Z", "datePublished": "2026-08-04T16:59:45.067Z", "dateUpdated": "2026-08-05T17:47:43.539Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "f23511db-6c3e-4e32-a477-6aa17d310630", "shortName": "TPLink", "dateUpdated": "2026-08-05T17:47:43.539Z" }, "title": "Authenticated Denial-of-Service Vulnerability in TP-Link Tapo P110", "problemTypes": [ { "descriptions": [ { "lang": "en", "cweId": "CWE-120", "description": "CWE-120 Buffer Copy without Checking Size of Input", "type": "CWE" } ] } ], "impacts": [ { "capecId": "CAPEC-100", "descriptions": [ { "lang": "en", "value": "CAPEC-100 Overflow Buffers" } ] } ], "affected": [ { "vendor": "TP-Link Systems Inc.", "product": "P110 v1", "versions": [ { "status": "affected", "version": "0", "lessThan": "V1_1.1.4 Build 260709", "versionType": "custom" } ], "defaultStatus": "unaffected" } ], "descriptions": [ { "lang": "en", "value": "Tapo P110 v1\nsmart Wi-Fi Plug contains an improper boundary validation vulnerability in the\nhandling of authenticated HTTP request bodies due to insufficient input\nvalidation before memory copy operations. This may lead to buffer overflow condition,\ncausing the web service process to crash.\n\n\n\n\n\nSuccessful exploitation\nmay cause the web service process to stop responding or restart, resulting in a\ndenial-of-service condition.", "supportingMedia": [ { "type": "text/html", "base64": false, "value": "

Tapo P110 v1\nsmart Wi-Fi Plug contains an improper boundary validation vulnerability in the\nhandling of authenticated HTTP request bodies due to insufficient input\nvalidation before memory copy operations. This may lead to buffer overflow condition,\ncausing the web service process to crash.

\n\n

Successful exploitation\nmay cause the web service process to stop responding or restart, resulting in a\ndenial-of-service condition. 

" } ] } ], "references": [ { "url": "https://www.tp-link.com/us/support/download/tapo-p110/v1/#Firmware-Release-Notes", "tags": [ "patch" ] }, { "url": "https://www.tp-link.com/en/support/download/tapo-p110/v1/#Firmware-Release-Notes", "tags": [ "patch" ] }, { "url": "https://www.tp-link.com/us/support/faq/5220/", "tags": [ "vendor-advisory" ] } ], "metrics": [ { "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ], "cvssV4_0": { "attackVector": "ADJACENT", "attackComplexity": "LOW", "attackRequirements": "NONE", "privilegesRequired": "NONE", "userInteraction": "NONE", "vulnConfidentialityImpact": "NONE", "subConfidentialityImpact": "NONE", "vulnIntegrityImpact": "NONE", "subIntegrityImpact": "NONE", "vulnAvailabilityImpact": "HIGH", "subAvailabilityImpact": "NONE", "exploitMaturity": "NOT_DEFINED", "Safety": "NOT_DEFINED", "Automatable": "NOT_DEFINED", "Recovery": "NOT_DEFINED", "valueDensity": "NOT_DEFINED", "vulnerabilityResponseEffort": "NOT_DEFINED", "providerUrgency": "NOT_DEFINED", "version": "4.0", "baseSeverity": "HIGH", "baseScore": 7.1, "vectorString": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N" } } ], "credits": [ { "lang": "en", "value": "Foo Min Zhan", "type": "finder" } ], "source": { "discovery": "UNKNOWN" }, "x_generator": { "engine": "Vulnogram 1.0.4" } }, "adp": [ { "metrics": [ { "other": { "type": "ssvc", "content": { "timestamp": "2026-08-04T17:23:57.677349Z", "id": "CVE-2026-15314", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "partial" } ], "role": "CISA Coordinator", "version": "2.0.3" } } } ], "title": "CISA ADP Vulnrichment", "providerMetadata": { "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2026-08-04T17:24:10.234Z" } } ] } }