Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-17176

Gravedad CVSS v4.0:
ALTA
Tipo:
CWE-78 Neutralización incorrecta de elementos especiales usados en un comando de sistema operativo (Inyección de comando de sistema operativo)
Fecha de publicación:
11/09/2026
Última modificación:
01/10/2026

Descripción

*** Pendiente de traducción *** An OS<br /> command injection vulnerability in the TDDP module of Deco BE11000 and Deco M9 Plus allows an<br /> adjacent network attacker to execute arbitrary commands with root privileges by<br /> sending a crafted UDP packet.<br /> <br /> <br /> <br /> Successful exploitation may lead to complete<br /> device compromise, including unauthorized command execution, modification of<br /> device settings, and loss of confidentiality, integrity, and availability