---
id: CVE-2026-17176
title: >-
  An OS

  command injection vulnerability in the TDDP module of Deco BE11000 allows an

  adjacent network attacker to execute arbitrary commands with root privileges
  by

  sending a crafted UDP packet.




  Successful exploitation may lead to compl…
summary: >-
  An OS

  command injection vulnerability in the TDDP module of Deco BE11000 allows an

  adjacent network attacker to execute arbitrary commands with root privileges
  by

  sending a crafted UDP packet.




  Successful exploitation may lead to compl…
severity: high
cvss: 7.7
cvssVector: 'CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L'
cwe:
  - CWE-78
vendor: TP-Link Systems Inc.
product: Deco BE11000 V2
affected:
  - deco_be11000_v2 < 1.3.5 Build 26071712
published: '2026-09-11'
updated: '2026-09-11'
sourceUpdated: '2026-09-11T15:21:12.850'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-17176'
references:
  - url: 'https://www.tp-link.com/en/support/faq/5293/'
    label: f23511db-6c3e-4e32-a477-6aa17d310630
  - url: 'https://www.tp-link.com/us/support/download/deco-be11000/#Firmware'
    label: f23511db-6c3e-4e32-a477-6aa17d310630
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-11T14:32:22.502230Z'
cvssSource: cna
ingestedAt: '2026-09-13T10:44:54.913Z'
epss: 0.03678
epssPercentile: 0.89238
---

## Overview

An OS
command injection vulnerability in the TDDP module of Deco BE11000 allows an
adjacent network attacker to execute arbitrary commands with root privileges by
sending a crafted UDP packet.



Successful exploitation may lead to complete
device compromise, including unauthorized command execution, modification of
device settings, and loss of confidentiality, integrity, and availability

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
