{"id":"CVE-2026-15314","published":"2026-08-04T17:16:46.313","lastModified":"2026-08-07T20:45:30.937","description":"Tapo P110 v1\nsmart Wi-Fi Plug contains an improper boundary validation vulnerability in the\nhandling of authenticated HTTP request bodies due to insufficient input\nvalidation before memory copy operations. This may lead to buffer overflow condition,\ncausing the web service process to crash.\n\n\n\n\n\nSuccessful exploitation\nmay cause the web service process to stop responding or restart, resulting in a\ndenial-of-service condition.","cvssScore":7.5,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwes":["CWE-120"],"vendors":["tp-link"],"products":["tapo p110 firmware","tapo p110"],"references":[{"url":"https://www.tp-link.com/en/support/download/tapo-p110/v1/#Firmware-Release-Notes","tags":["Release Notes"]},{"url":"https://www.tp-link.com/us/support/download/tapo-p110/v1/#Firmware-Release-Notes","tags":["Release Notes"]},{"url":"https://www.tp-link.com/us/support/faq/5220/","tags":["Vendor Advisory"]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The flaw is an improper boundary validation vulnerability in the handling of authenticated HTTP request bodies, leading to potential buffer overflow and denial-of-service conditions. This matters because it can cause the web service process to crash upon exploitation.","exploitability":"Exploitation requires specific knowledge of the vulnerability and authenticated access; it may be moderately difficult given the need for authentication but not complex.","blast_radius":"If exploited, this could result in a denial-of-service condition affecting the smart Wi-Fi plug's web service process, impacting device functionality.","remediation":"Update to the latest firmware version to address the vulnerability and ensure proper input validation.","tags":["buffer-overflow","denial-of-service","firmware-update","http-request"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-08-11T06:54:09.725Z"}}