Beveiligingsadvies

CVE-2026-6250

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-06-11 20:46:09
Laatst bijgewerkt 2026-06-12 15:41:58
Toegewezen door TPLink
CVSS-score 7.0
Status PUBLISHED

Beschrijving

An authenticated format string vulnerability exists in the ONVIF service of Tapo C110 v2 due to improper handling of user-controlled input.  Externally controlled data is interpreted as a format string, which can be used to manipulate stack memory, including control flow data such as return addresses. A remote authenticated attacker may redirect execution flow to existing internal functions, triggering an unauthorized factory reset, leading to loss of configuration, deletion of stored credentials and service disruption.