CVE-2026-15314: Authenticated Denial-of-Service Vulnerability in TP-Link Tapo P110
Tapo P110 v1 smart Wi-Fi Plug contains an improper boundary validation vulnerability in the handling of authenticated HTTP request bodies due to insufficient input validation before memory copy operations. This may lead to buffer overflow condition, causing the web service process to crash.
Successful exploitation may cause the web service process to stop responding or restart, resulting in a denial-of-service condition.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-15314?
CVE-2026-15314 has a severity rating of high, with a CVSS score of 7.1.
What vulnerability is associated with CVE-2026-15314?
CVE-2026-15314 is characterized by an authenticated denial-of-service vulnerability in the TP-Link Tapo P110 smart plug.
How do I fix CVE-2026-15314?
To mitigate CVE-2026-15314, update your TP-Link Tapo P110 firmware to the latest version as provided by the manufacturer.
What can happen if CVE-2026-15314 is exploited?
Exploitation of CVE-2026-15314 may lead to a buffer overflow, causing the web service process of the TP-Link Tapo P110 to crash.
Which products are affected by CVE-2026-15314?
The TP-Link Tapo P110 (v1) smart Wi-Fi plug is the affected product for CVE-2026-15314.