TP-Link Deco BE25 Path Traversal Vulnerability Allowing Arbitrary File Read or Denial-of-Service

Vulnerability

A path traversal vulnerability has been identified in the TP-Link Deco BE25 v1.0 web modules, allowing authenticated adjacent attackers to read arbitrary files or cause a denial-of-service. This vulnerability arises from improper limitations on pathnames, enabling exploitation by traversing directories to access restricted files.

Impact

Exploitation of this vulnerability could lead to unauthorized reading of files or causing a denial-of-service condition on the device.

Remediation

Users are advised to update to the latest firmware version. The updated firmware can be downloaded from the TP-Link official website for the respective region.

Added: Mar 2, 2026, 6:32 PM
Updated: Mar 2, 2026, 9:12 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
3.5
remediation
0.0
relevance
3.4
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.