CVE-2026-15314
7.5 HIGHPublished 2026-08-04 · Updated 2026-08-07
AI risk analysis
- Summary
- The flaw is an improper boundary validation vulnerability in the handling of authenticated HTTP request bodies, leading to potential buffer overflow and denial-of-service conditions. This matters because it can cause the web service process to crash upon exploitation.
- Exploitability
- Exploitation requires specific knowledge of the vulnerability and authenticated access; it may be moderately difficult given the need for authentication but not complex.
- Blast radius
- If exploited, this could result in a denial-of-service condition affecting the smart Wi-Fi plug's web service process, impacting device functionality.
- Prioritized remediation
- Update to the latest firmware version to address the vulnerability and ensure proper input validation.
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
Tapo P110 v1 smart Wi-Fi Plug contains an improper boundary validation vulnerability in the handling of authenticated HTTP request bodies due to insufficient input validation before memory copy operations. This may lead to buffer overflow condition, causing the web service process to crash. Successful exploitation may cause the web service process to stop responding or restart, resulting in a denial-of-service condition.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weaknesses
CWE-120
Vendors
tp-link
Products
tapo p110 firmware, tapo p110
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.