216.73.217.22

CVE-2026-0654

· Published 02/03/2026 18:16 · Modified 02/03/2026 20:29

Labels: CVE-2026-0654 2026-03-02CVE-2026-0654CWE-78f23511db-6c3e-4e32-a477-6aa17d310630

Essential information

Published
02/03/2026 18:16
Modified
02/03/2026 20:29
Author
Creator
CVSS
8.5 HIGH (v3) 8.5 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Improper input handling in the administration web interface on TP-Link Deco BE25 v1.0 allows crafted input to be executed as part of an OS command. An authenticated adjacent attacker may execute arbitrary commands via crafted configuration file, impacting confidentiality, integrity and availability of the device. This issue affects Deco BE25 v1.0: through 1.1.1 Build 20250822.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
f23511db-6c3e-4e32-a477-6aa17d310630
NVD
View on NVD

Affected products (CPE)

ProductCPE
tp-link / deco cpe:2.3:a:tp-link:deco:1.0-1.1.1:*:*:*:*:*:*:*

References