CyberRota
← Ana sayfaya dön

CVE-2026-6250

HIGH · CVSS 8.1 EPSS %0.46

Kaynak: NVD + CISA KEV + EPSS · Yayınlanma: 2026-06-11T22:16:57.870 · Çekilme zamanı: 2026-06-30T18:19:53.943326+00:00

CyberRota Yorumu

Bellek tüketimine neden olabilir. Uzaktan istismar edilebilir olabilir.

CVE
CVE-2026-6250
Severity
HIGH
CVSS
8.1
EPSS
%0.46

Orijinal NVD Açıklaması

An authenticated format string vulnerability exists in the ONVIF service of Tapo C110 v2 due to improper handling of user-controlled input.  Externally controlled data is interpreted as a format string, which can be used to manipulate stack memory, including control flow data such as return addresses. A remote authenticated attacker may redirect execution flow to existing internal functions, triggering an unauthorized factory reset, leading to loss of configuration, deletion of stored credentials and service disruption.