Junglewise Threat Intelligence

CVE-2026-15314: TP-Link Tapo P110 buffer overflow in HTTP request handling

CVE-2026-15314 · Severity: high · CVSS 7.5 · Published 2026-08-04

Vendors: TP-Link.

Executive brief

The Tapo P110 is a smart Wi-Fi plug used to remotely control power to appliances and monitor energy consumption. An authenticated attacker can exploit improper input validation in the web service to cause a buffer overflow, crashing the device's web service and rendering it unresponsive or requiring a restart, leading to loss of remote control and monitoring capabilities.

Technical details

This is a stack or heap buffer overflow vulnerability arising from insufficient input validation before memory copy operations in authenticated HTTP request body handling. The vulnerability exists in the device's web service and requires the attacker to be authenticated (have valid device credentials). By crafting an oversized HTTP request body that exceeds the buffer boundary, an attacker can trigger the overflow condition, causing the web service process to crash or restart, resulting in a denial-of-service condition. A patch or firmware update is presumably available from TP-Link through their support channels.

Affected products

  • TP-Link Tapo P110 V1

Timeline

  • 2026-08-04: disclosed

References