Home
HIGH: 8.0 CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H firmware versions prior to "Deco BE65 Pro(JP)_V1_1.1.2 Build 20250123"
affected
Description
OS command injection vulnerability exists in Deco BE65 Pro firmware versions prior to "Deco BE65 Pro(JP)_V1_1.1.2 Build 20250123". If this vulnerability is exploited, an arbitrary OS command may be executed by the user who can log in to the device.
Problem types
Improper neutralization of special elements used in an OS command ('OS Command Injection')
Product status
References
www.tp-link.com/jp/support/download/deco-be65-pro/