---
cve: "CVE-2026-15314"
severity: "HIGH"
cvss: 7.1
epss: "0.5%"
vendor: "TP-Link Systems Inc."
kev: false
exploited: false
published: "2026-08-04 17:16:46"
tags: [cve, security, high]
source: tsecurity.de CVE-Dossier
exported: "2026-09-21T10:01:27+02:00"
---

# CVE-2026-15314

> 7.1 HIGH

## Beschreibung

Tapo P110 v1
smart Wi-Fi Plug contains an improper boundary validation vulnerability in the
handling of authenticated HTTP request bodies due to insufficient input
validation before memory copy operations. This may lead to buffer overflow condition,
causing the web service process to crash.





Successful exploitation
may cause the web service process to stop responding or restart, resulting in a
denial-of-service condition.

## CVSS-Vektor

```
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Benachbart | warn |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |

## Referenzen

- <https://www.tp-link.com/us/support/download/tapo-p110/v1/#Firmware-Release-Notes>
- <https://www.tp-link.com/en/support/download/tapo-p110/v1/#Firmware-Release-Notes>
- <https://www.tp-link.com/us/support/faq/5220/>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-15314) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
