CVE-2025-32107: TP-Link Corporation Limited Deco BE65 Pro
High severity, CVSS 8.0. EPSS: 1.6% chance of exploitation in the next 30 days.
OS command injection vulnerability exists in Deco BE65 Pro firmware versions prior to "Deco BE65 Pro(JP)_V1_1.1.2 Build 20250123". If this vulnerability is exploited, an arbitrary OS command may be executed by the user who can log in to the device.
Affected products
- TP-Link Corporation Limited Deco BE65 Pro
Published 2025-04-11. Last modified 2026-06-17.