---
id: CVE-2026-15314
title: |-
  Tapo P110 v1
  smart Wi-Fi Plug contains an improper boundary validation vulnerability in the
  handling of authenticated HTTP request bodies due to insufficient input
  validation before memory copy operations
summary: |-
  Tapo P110 v1
  smart Wi-Fi Plug contains an improper boundary validation vulnerability in the
  handling of authenticated HTTP request bodies due to insufficient input
  validation before memory copy operations. This may lead to buffer overflo…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-120
vendor: tp-link
product: tapo_p110_firmware
affected:
  - tapo_p110_firmware < 1.1.4
patched:
  - tapo_p110_firmware 1.1.4
published: '2026-08-04'
updated: '2026-08-07'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-15314'
references:
  - url: >-
      https://www.tp-link.com/en/support/download/tapo-p110/v1/#Firmware-Release-Notes
    label: f23511db-6c3e-4e32-a477-6aa17d310630
  - url: >-
      https://www.tp-link.com/us/support/download/tapo-p110/v1/#Firmware-Release-Notes
    label: f23511db-6c3e-4e32-a477-6aa17d310630
  - url: 'https://www.tp-link.com/us/support/faq/5220/'
    label: f23511db-6c3e-4e32-a477-6aa17d310630
tags:
  - nvd
epss: 0.00759
epssPercentile: 0.53259
ingestedAt: '2026-08-08T19:28:35.170Z'
---

## Overview

Tapo P110 v1
smart Wi-Fi Plug contains an improper boundary validation vulnerability in the
handling of authenticated HTTP request bodies due to insufficient input
validation before memory copy operations. This may lead to buffer overflow condition,
causing the web service process to crash.





Successful exploitation
may cause the web service process to stop responding or restart, resulting in a
denial-of-service condition.

## Affected

- `tapo_p110_firmware < 1.1.4`

## Remediation

Upgrade past the affected range:

- `tapo_p110_firmware 1.1.4`
