Executive brief
The TP-Link Deco BE11000 is a mesh WiFi system that provides home network coverage and connectivity. A vulnerability in its TDDP (TP-Link Device Discovery Protocol) module allows an attacker on the same network to send a specially crafted UDP packet and execute arbitrary commands with root privileges, potentially taking complete control of the device, modifying settings, and accessing all data on the network.
Technical details
This is an OS command injection vulnerability in the TDDP module of the Deco BE11000, where unsanitized input in UDP packets can be passed to system command execution functions. An adjacent network attacker can craft a malicious UDP packet to exploit this flaw without authentication or user interaction. Successful exploitation grants root-level command execution, enabling complete device compromise including unauthorized configuration changes and loss of confidentiality, integrity, and availability. TP-Link has issued firmware version 1.3.5 Build 26071712 as a fix for hardware version v2.
Affected products
- TP-Link Deco BE11000 v2 prior to firmware 1.3.5 Build 26071712
Timeline
- 2026-09-11: disclosed
- 2026-09-10: patched: Firmware 1.3.5 Build 26071712 for hardware version v2