cvedb.io
CVE-2026-0654
HIGH · CVSS 8
EPSS exploitation probability: 0%
Published 2026-03-02T18:16:25.983 · Last modified 2026-06-17T10:11:09.347

Summary

Improper input handling in the administration web interface on TP-Link Deco BE25 v1.0 allows crafted input to be executed as part of an OS command. An authenticated adjacent attacker may execute arbitrary commands via crafted configuration file, impacting confidentiality, integrity and availability of the device. This issue affects Deco BE25 v1.0: through 1.1.1 Build 20250822.

Affected products

tp-link — deco_be25_firmware

Does this affect you?

Add your gear to cvedb and we'll alert you only when tp-link ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.