CVE-2026-17176 PUBLISHED

OS command injection Vulnerability in Deco BE11000

Assigner: TPLink
Reserved: 24.07.2026 Published: 10.09.2026 Updated: 10.09.2026

An OS command injection vulnerability in the TDDP module of Deco BE11000 allows an adjacent network attacker to execute arbitrary commands with root privileges by sending a crafted UDP packet.

Successful exploitation may lead to complete device compromise, including unauthorized command execution, modification of device settings, and loss of confidentiality, integrity, and availability

Metrics

CVSS Vector: CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L
CVSS Score: 7.7

Product Status

Vendor TP-Link Systems Inc.
Product Deco BE11000 V2
Versions Default: unaffected
  • affected from 0 to 1.3.5 Build 26071712 (excl.)

References

Problem Types

  • CWE-78 Improper neutralization of special elements used in an OS command ('OS command injection') CWE

Impacts

  • CAPEC-248 Command Injection