CVE-2026-0654 PUBLISHED

Command injection on TP-Link Deco BE25

Assigner: TPLink
Reserved: 06.01.2026 Published: 02.03.2026 Updated: 11.03.2026

Improper input handling in the administration web interface on TP-Link Deco BE25 v1.0 allows crafted input to be executed as part of an OS command. An authenticated adjacent attacker may execute arbitrary commands via crafted configuration file, impacting confidentiality, integrity and availability of the device. This issue affects Deco BE25 v1.0: through 1.1.1 Build 20250822.

Metrics

CVSS Vector: CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L
CVSS Score: 8.5

Product Status

Vendor TP-Link Systems Inc.
Product Deco BE25 v1.0
Versions Default: unaffected
  • affected from 0 to 1.1.1 Build 20250822 (incl.)

Credits

  • caprinuxx finder

References

Problem Types

  • CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CWE

Impacts

  • CAPEC-88 OS Command Injection