Update your Routers Now: TP-Link High-Severity Deco BE11000 Flaw Grants Root

We choose to run an ad-free site, so this post may contain affiliate links. If you wish to support us and use these links to buy something, we may earn a commission. Learn more in our affiliate disclosures.

TP-Link has released a security fix for a serious flaw in its Deco BE11000 mesh Wi-Fi system that could let an attacker on the same local network run commands on the router as root. The issue, disclosed on September 10, 2026 and tracked as CVE-2026-17176, is rated High severity, affects only hardware version V2 of the Deco BE11000, and is fixed in firmware version 1.3.5 Build 26071712. Anyone using this specific hardware version is urged to install the new firmware.

What CVE-2026-17176 Does and Why It Matters

CVE-2026-17176 is an OS command injection vulnerability in the Deco BE11000’s TDDP module, which handles certain UDP packets sent to the device. Because the device does not properly validate input received in certain UDP packets, an attacker can send data that includes shell metacharacters and get the router to run arbitrary operating system commands. Those commands run with root-level privileges.

TP-Link’s rating for this flaw is CVSS v4.0 7.7, which falls into the High severity range. The full vector string is CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L. In practical terms, that combination reflects that the attack is technically straightforward, does not need a login or any help from the user, and can cause serious damage to the device’s confidentiality, integrity, and availability. One metric cuts the other way: AT:P means a successful attack also depends on specific deployment and execution conditions being present on the target device, so it does not succeed against every unit in every setup.

If someone manages to exploit this vulnerability, they can fully compromise the Deco unit. That can include changing network settings, running their own software on the device, and disrupting or shutting down the connection it manages. Because mesh systems often sit at the center of a home network, control of the router can also expose traffic that passes through it.

Who Is Actually at Risk: Local Network, Not the Whole Internet

The critical detail with this bug is how close an attacker has to be. The attack vector is marked as “Adjacent” (AV:A) in the CVSS score, which means the attacker must already be on, or directly connected to, the same local network segment as the Deco BE11000. This is not a case where someone across the internet can just scan for your router and hit it from anywhere.

That local requirement shapes the real-world risk. Scenarios that matter include shared or guest Wi-Fi networks where you do not fully trust everyone connected, or a situation where a device inside your home is already compromised and can send crafted packets to the Deco unit. In those cases, because the vulnerability needs no existing privileges (PR:N) and no user interaction (UI:N), a malicious actor or malware already inside the network could attack the router quietly and with low effort (AC:L).

For typical home users who do not share their Wi-Fi with strangers, the exposure is narrower than a direct internet-facing flaw, but it is still serious. Mesh systems often bridge many devices, and a compromised router can be a strong foothold for further activity on the network. That is why TP-Link’s recommendation is simple: if you have an affected Deco BE11000 hardware version, install the fixed firmware.

What Changed and How TP-Link Fixed It

The root cause of CVE-2026-17176 is insufficient validation of input received in UDP packets handled by the TDDP module. When that module processes packets that can include shell metacharacters without filtering or sanitizing them, it opens the door for command injection. Attackers who understand the protocol can package their commands inside those specially crafted UDP packets.

TP-Link has addressed the issue through a firmware update for the Deco BE11000 V2. The patched firmware version is 1.3.5 Build 26071712. Installing this version closes the injection path in the TDDP module so that arbitrary operating system commands can no longer be triggered in this way.

Only the Deco BE11000 with hardware version V2 is affected by CVE-2026-17176. Owners of the affected hardware version should update to the latest firmware that contains the patch.

How to Check Your Deco Model, Hardware Version, and Firmware

Since only Deco BE11000 hardware version V2 is affected, the first step is to confirm exactly which hardware version you own. You can do this in two main ways: by checking the physical label on the device, and by looking at the information shown in the Deco app. On the device itself, the product label on the underside or back usually lists the model name “Deco BE11000” and a “Hardware Version” field, such as “V2”.

In the Deco app, there is a section that shows device details for each node in your mesh system. When you open the details for a node, you can typically see the model name, hardware version, and the current firmware version running on that unit. Look for anything labeled “Hardware Version” or similar and confirm that it says “V2” before treating your system as affected by CVE-2026-17176. One wrinkle is worth knowing here: TP-Link’s firmware download pages label this hardware “V2.6” rather than a bare “V2,” and the patched file itself is named for that version. If your label or app entry reads V2.6, treat it as the same affected hardware generation rather than a different, unaffected one.

While you are there, also note the firmware version. You are looking to see whether it is already at 1.3.5 Build 26071712 or higher. If the version is lower than that, and your hardware version is V2, you should plan to update as soon as you can.

How to Update Deco Firmware and Why Auto-Updates Help

Updating a Deco mesh system’s firmware is generally handled through the Deco app. When a new firmware version is available, the app usually displays a notice or badge that an update is ready for one or more units in your network. From there, you can start the update process, which downloads the new firmware to each node and reboots it once the install is complete.

The exact path and button names depend on the app version, but the process usually involves opening your network in the app, going into the settings or management area, and choosing an option to check for or install firmware updates. During the update, your internet connection might be briefly interrupted while the Deco units restart. It is a good idea to schedule this when no one in the house is doing something critical online.

For a mesh system that acts as the central point of your home network, turning on automatic firmware updates is a strong safety measure. Auto-updates mean that when a security fix like the one for CVE-2026-17176 is released, your Deco units can upgrade without you having to remember to check. That reduces the time you stay exposed to known problems and cuts down on manual work, especially if you have several nodes.

Owners of the Deco BE11000 hardware version V2 should check their hardware and firmware versions, then install firmware 1.3.5 Build 26071712 or later as soon as they can. This closes a High severity flaw that could let someone already on your local network take root-level control of the router. Updating now is the straightforward way to lock this particular door.

View the original security advisory.

Latest News