{"id":"CVE-2026-15314","title":"Tapo P110 v1\nsmart Wi-Fi Plug contains an improper boundary validation vulnerability in the\nhandling of authenticated HTTP request bodies due to insufficient input\nvalidation before memory copy operations","summary":"Tapo P110 v1\nsmart Wi-Fi Plug contains an improper boundary validation vulnerability in the\nhandling of authenticated HTTP request bodies due to insufficient input\nvalidation before memory copy operations. This may lead to buffer overflo…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-120"],"vendor":"tp-link","product":"tapo_p110_firmware","affected":["tapo_p110_firmware < 1.1.4"],"patched":["tapo_p110_firmware 1.1.4"],"published":"2026-08-04","updated":"2026-08-07","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-15314","references":[{"url":"https://www.tp-link.com/en/support/download/tapo-p110/v1/#Firmware-Release-Notes","label":"f23511db-6c3e-4e32-a477-6aa17d310630"},{"url":"https://www.tp-link.com/us/support/download/tapo-p110/v1/#Firmware-Release-Notes","label":"f23511db-6c3e-4e32-a477-6aa17d310630"},{"url":"https://www.tp-link.com/us/support/faq/5220/","label":"f23511db-6c3e-4e32-a477-6aa17d310630"}],"tags":["nvd"],"epss":0.00499,"epssPercentile":0.41659,"ingestedAt":"2026-08-08T19:28:35.170Z","slug":"CVE-2026-15314","body":"## Overview\n\nTapo P110 v1\nsmart Wi-Fi Plug contains an improper boundary validation vulnerability in the\nhandling of authenticated HTTP request bodies due to insufficient input\nvalidation before memory copy operations. This may lead to buffer overflow condition,\ncausing the web service process to crash.\n\n\n\n\n\nSuccessful exploitation\nmay cause the web service process to stop responding or restart, resulting in a\ndenial-of-service condition.\n\n## Affected\n\n- `tapo_p110_firmware < 1.1.4`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `tapo_p110_firmware 1.1.4`","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}