OS Command Injection Vulnerability in Deco BE11000 by TP-Link
CVE-2026-17176

7.7HIGH

Key Information:

Vendor
CVE Published:
10 September 2026

What is CVE-2026-17176?

An OS command injection vulnerability exists in the TDDP module of the Deco BE11000 device. This flaw allows an adjacent network attacker to send specially crafted UDP packets that can execute arbitrary commands with root privileges. Successful exploitation can lead to a complete compromise of the device, risking unauthorized command execution, alterations to device settings, and jeopardizing the confidentiality, integrity, and availability of the device.

Affected Version(s)

Deco BE11000 V2 0 < 1.3.5 Build 26071712

References

CVSS V4

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.