CVE-2026-17176: TP-Link Systems Inc Deco BE11000 v2

High severity, CVSS 7.7. EPSS: 5% chance of exploitation in the next 30 days.

An OS command injection vulnerability in the TDDP module of Deco BE11000 and Deco M9 Plus allows an adjacent network attacker to execute arbitrary commands with root privileges by sending a crafted UDP packet. Successful exploitation may lead to complete device compromise, including unauthorized command execution, modification of device settings, and loss of confidentiality, integrity, and availability

Affected products

  • TP-Link Systems Inc Deco BE11000 v2: before 1.3.5 Build 26071712 (fixed in 1.3.5 Build 26071712)
  • TP-Link Systems Inc Deco m9 Plus v2: before 1.9.2 Build 20260818 (fixed in 1.9.2 Build 20260818)

Published 2026-09-11. Last modified 2026-10-01.