CVE-2026-17176
Severity CVSS v4.0:
HIGH
Type:
CWE-78
OS Command Injections
Publication date:
11/09/2026
Last modified:
01/10/2026
Description
An OS<br />
command injection vulnerability in the TDDP module of Deco BE11000 and Deco M9 Plus allows an<br />
adjacent network attacker to execute arbitrary commands with root privileges by<br />
sending a crafted UDP packet.<br />
<br />
<br />
<br />
Successful exploitation may lead to complete<br />
device compromise, including unauthorized command execution, modification of<br />
device settings, and loss of confidentiality, integrity, and availability
Impact
Base Score 4.0
7.70
Severity 4.0
HIGH


