ZeroHour

CVE-2026-17176

moderate

Root OS Command Injection in TP-Link Deco BE11000 TDDP Module

CVSS 4.0
7.7 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-17176 is an OS command injection vulnerability (CWE-78) in the TDDP (TP-Link Device Debug Protocol) module of the TP-Link Deco BE11000 mesh Wi-Fi router. An attacker already positioned on an adjacent network segment (the same LAN/Wi-Fi) can trigger it by sending a crafted UDP packet to the device's TDDP service; per the CVSS 4.0 vector (AV:A/PR:N/UI:N with AT:P), no credentials or user interaction are required, but certain atypical environmental conditions must be present for the attack to succeed. Successful exploitation yields arbitrary command execution with root privileges, allowing complete device compromise, unauthorized modification of device settings, and loss of confidentiality, integrity, and availability. Only Deco BE11000 units are implicated by the available data, and practical exposure is limited to attackers who already have a foothold on the local network (e.g., a guest or compromised client device). There are no reports of in-the-wild exploitation, no public proof-of-concept, the flaw is not in CISA's KEV, and no fixed firmware version is specified in the available data.

What to do: No fixed firmware version is listed in the available data, so monitor TP-Link's security advisory page for a patched Deco BE11000 release and apply it as soon as it is published. Until then, reduce adjacent-network risk by keeping untrusted, IoT, and guest devices off the primary LAN segment hosting the Deco units, since the UDP-based attack path requires only local access and grants root. Watch for a public PoC given the simple single-packet attack surface, and treat any report of LAN-side scanning of UDP debug services as a signal to prioritize patching.

Affected
TP-Link Deco BE11000 (mesh Wi-Fi router, TDDP module)
Estimated exposure
moderatelikely on the order of tens of thousands of installed units; exact install base unpublished — No public install-base or internet-scan data exists for this LAN-only flaw; the estimate extrapolates from the BE11000 being a single recent premium Wi-Fi 7 model within TP-Link's otherwise high-volume Deco mesh line, which is typically…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An OS command injection vulnerability in the TDDP module of Deco BE11000 allows an adjacent network attacker to execute arbitrary commands with root privileges by sending a crafted UDP packet. Successful exploitation may lead to complete device compromise, including unauthorized command execution, modification of device settings, and loss of confidentiality, integrity, and availability

Weakness
CWE-78
Vector
CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.