๐Ÿ” CVE Alert

CVE-2026-17176

UNKNOWN 0.0

OS command injection Vulnerability in Deco BE11000

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

An OS command injection vulnerability in the TDDP module of Deco BE11000 allows an adjacent network attacker to execute arbitrary commands with root privileges by sending a crafted UDP packet. Successful exploitation may lead to complete device compromise, including unauthorized command execution, modification of device settings, and loss of confidentiality, integrity, and availability

CWE CWE-78
Vendor tp-link systems inc.
Product deco be11000 v2
Published Sep 10, 2026
Last Updated Sep 11, 2026
Stay Ahead of the Next One

Get instant alerts for tp-link systems inc. deco be11000 v2

Be the first to know when new unknown vulnerabilities affecting tp-link systems inc. deco be11000 v2 are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

TP-Link Systems Inc. / Deco BE11000 V2
0 < 1.3.5 Build 26071712

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
tp-link.com: https://www.tp-link.com/us/support/download/deco-be11000/#Firmware tp-link.com: https://www.tp-link.com/en/support/faq/5293/