Tp Link Systems · Deco Be11000 V2 · CVE-2026-17176
An OS
command injection vulnerability in the TDDP module of Deco BE11000 and Deco M9 Plus allows an
adjacent network attacker to execute arbitrary commands with root privileges by
sending a crafted UDP packet.
Successful exploitation may lead to complete
device compromise, including unauthorized command execution, modification of
device settings, and loss of confidentiality, integrity, and availability