GHSA-g92m-rv6c-v268High

An OS command injection vulnerability in the TDDP module of Deco BE11000 allows an adjacent...

Published
September 11, 2026
Last Modified
October 1, 2026

🔗 CVE IDs covered (1)

📋 Description

An OS command injection vulnerability in the TDDP module of Deco BE11000 allows an adjacent network attacker to execute arbitrary commands with root privileges by sending a crafted UDP packet.

Successful exploitation may lead to complete device compromise, including unauthorized command execution, modification of device settings, and loss of confidentiality, integrity, and availability

🔗 References (6)