GHSA-g92m-rv6c-v268High
An OS command injection vulnerability in the TDDP module of Deco BE11000 allows an adjacent...
🔗 CVE IDs covered (1)
📋 Description
An OS command injection vulnerability in the TDDP module of Deco BE11000 allows an adjacent network attacker to execute arbitrary commands with root privileges by sending a crafted UDP packet.
Successful exploitation may lead to complete device compromise, including unauthorized command execution, modification of device settings, and loss of confidentiality, integrity, and availability
🔗 References (6)
- https://nvd.nist.gov/vuln/detail/CVE-2026-17176
- https://www.tp-link.com/en/support/faq/5293
- https://www.tp-link.com/us/support/download/deco-be11000/#Firmware
- https://www.tp-link.com/en/support/download/deco-m9-plus/v2
- https://www.tp-link.com/us/support/download/deco-m9-plus/v2/#Firmware
- https://github.com/advisories/GHSA-g92m-rv6c-v268