CVE-2026-6250
Description
An authenticated format string vulnerability in the Tapo C110 v2 ONVIF service allows a remote attacker to trigger an unauthorized factory reset.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
An authenticated format string vulnerability in the Tapo C110 v2 ONVIF service allows a remote attacker to trigger an unauthorized factory reset.
Vulnerability
An authenticated format string vulnerability exists in the ONVIF service of Tapo C110 v2 (firmware versions below 1.5.4 Build 260428 Rel.64344n) [4]. User-controlled input is improperly handled and interpreted as a format string, allowing manipulation of stack memory, including control flow data such as return addresses [4].
Exploitation
A remote attacker must first authenticate to the ONVIF service. With valid credentials, the attacker can supply a crafted format string as part of an ONVIF request [4]. The vulnerable service then processes this input, enabling memory corruption that redirects execution flow [4].
Impact
By redirecting execution flow to existing internal functions, the attacker can trigger an unauthorized factory reset of the device [4]. This results in loss of configuration, deletion of stored credentials, and service disruption [4].
Mitigation
TP-Link has released firmware version 1.5.4 Build 260428 Rel.64344n to fix this vulnerability [4]. Users with affected Tapo C110 v2 devices should update immediately via the TP-Link download center [1][3][4]. No workaround is documented; the only mitigation is applying the firmware update.
AI Insight generated on Jun 11, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.
References
4News mentions
0No linked articles in our index yet.