CVE-2026-17176

Severity CVSS v4.0:
HIGH
Type:
CWE-78 OS Command Injections
Publication date:
11/09/2026
Last modified:
01/10/2026

Description

An OS<br /> command injection vulnerability in the TDDP module of Deco BE11000 and Deco M9 Plus allows an<br /> adjacent network attacker to execute arbitrary commands with root privileges by<br /> sending a crafted UDP packet.<br /> <br /> <br /> <br /> Successful exploitation may lead to complete<br /> device compromise, including unauthorized command execution, modification of<br /> device settings, and loss of confidentiality, integrity, and availability