Executive brief
A security vulnerability exists in the TP-Link Tapo C110 v2 home security camera. An authorized user could exploit this flaw to remotely force the camera to perform a factory reset. This results in a complete loss of device configuration, deletion of stored credentials, and a disruption of the camera's monitoring services.
Technical details
An authenticated format string vulnerability (CWE-134) exists in the ONVIF service of the TP-Link Tapo C110 v2. The issue stems from improper handling of user-controlled input where externally provided data is interpreted as a format string. This allows a remote authenticated attacker to manipulate stack memory and control flow data, such as return addresses. By redirecting execution flow to internal functions, an attacker can trigger an unauthorized factory reset, leading to a denial of service and loss of configuration. The vulnerability is reachable via the network (adjacent) and requires low privileges.
Affected products
- TP-Link Tapo C110 v2
Timeline
- 2026-06-11: disclosed
- 2026-06-11: advisory