CVE-2026-17176

Summary

An OS command injection vulnerability in the TDDP module of Deco BE11000 allows an adjacent network attacker to execute arbitrary commands with root privileges by sending a crafted UDP packet.

Successful exploitation may lead to complete device compromise, including unauthorized command execution, modification of device settings, and loss of confidentiality, integrity, and availability

Affected Software

VendorProductVersion RangeStatus
TP-Link Systems Inc.Deco BE11000 V20 < 1.3.5 Build 26071712affected

Weaknesses

  • CWE-78: CWE-78 Improper neutralization of special elements used in an OS command ('OS command injection')

References