[CVE-2026-17176] An OS command injection vulnerability in the TDDP module of

CVE-2026-17176 | CVSS: N/A

An OS
command injection vulnerability in the TDDP module of Deco BE11000 allows an
adjacent network attacker to execute arbitrary commands with root privileges by
sending a crafted UDP packet.

Successful exploitation may lead to complete
device compromise, including unauthorized command execution, modification of
device settings, and loss of confidentiality, integrity, and availability

参考链接:
https://www.tp-link.com/en/support/faq/5293/
https://www.tp-link.com/us/support/download/deco-be11000/#Firmware

📌 数据来源: NVD 官方

⚠️ 合规声明: 本文内容仅用于网络安全合规学习、科研与授权测试用途。严禁用于任何未授权行为,违者自行承担全部法律责任。
滚动至顶部