CVE-2026-17176
Gravedad CVSS v4.0:
ALTA
Tipo:
CWE-78
Neutralización incorrecta de elementos especiales usados en un comando de sistema operativo (Inyección de comando de sistema operativo)
Fecha de publicación:
11/09/2026
Última modificación:
01/10/2026
Descripción
*** Pendiente de traducción *** An OS<br />
command injection vulnerability in the TDDP module of Deco BE11000 and Deco M9 Plus allows an<br />
adjacent network attacker to execute arbitrary commands with root privileges by<br />
sending a crafted UDP packet.<br />
<br />
<br />
<br />
Successful exploitation may lead to complete<br />
device compromise, including unauthorized command execution, modification of<br />
device settings, and loss of confidentiality, integrity, and availability
Impacto
Puntuación base 4.0
7.70
Gravedad 4.0
ALTA


