TP-Link Deco BE25 Command Injection Vulnerability

Vulnerability

A command injection vulnerability has been identified in the TP-Link Deco BE25 v1.0 administration web interface. This vulnerability allows authenticated adjacent attackers to execute arbitrary OS commands by injecting crafted input through a configuration file. The issue affects versions through 1.1.1 Build 20250822.

Impact

Exploitation of this vulnerability allows for arbitrary command execution on the affected device.

Remediation

Users are advised to update to the latest firmware version. The updated firmware can be downloaded from the TP-Link official website, selecting the appropriate regional site.

Added: Mar 2, 2026, 6:32 PM
Updated: Mar 2, 2026, 9:11 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
3.5
remediation
0.0
relevance
3.4
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.