CVE-2026-6250
概要

An
authenticated format string vulnerability exists in the ONVIF service of Tapo
C110 v2 due to improper handling of user-controlled input.  Externally controlled data is interpreted as
a format string, which can be used to manipulate stack memory, including
control flow data such as return addresses.

A remote
authenticated attacker may redirect execution flow to existing internal
functions, triggering an unauthorized factory reset, leading to loss of
configuration, deletion of stored credentials and service disruption.

公表日 2026年6月12日7:16
登録日 2026年6月13日4:16
最終更新日 2026年6月13日1:06
関連情報、対策とツール
共通脆弱性一覧