Smart Home Assistant

TP-Link Deco BE11000 Vulnerability: Update Your Firmware Now

SepehrBy Sepehr· 12 September 2026· Updated 12 September 2026
✓ Independent — no paid placements✓ UK-tested in real homes✓ Cited sources
White mesh Wi-Fi router unit standing upright on a table with status lights visible on the front panel.

Key takeaways

  • CVE-2026-17176 is a high-severity (CVSS 7.7) OS command injection flaw in the TP-Link Deco BE11000's TDDP module.
  • An attacker already on the same network can send a crafted UDP packet to run root commands on the router.
  • TP-Link disclosed the flaw on 10 September 2026 and has already released fixed firmware 1.3.5, build 26071712.
  • Update through the Deco app under More → Firmware Upgrade — it pushes the fix to every satellite unit in the mesh.
  • A compromised router can expose every device behind it, including a Home Assistant instance, so patching promptly matters more than replacing the hardware.
On this page[tap to expand]

The TP-Link Deco BE11000 vulnerability is a high-severity OS command injection flaw, tracked as CVE-2026-17176, that lets an attacker on the same network send a crafted UDP packet and run commands on the router with root privileges. TP-Link disclosed it on 10 September 2026 and has already shipped a fixed firmware build.

What was announced about the Deco BE11000 vulnerability?

TP-Link's own security advisory describes an OS command injection vulnerability in the TDDP module of the Deco BE11000 (hardware version 2), the company's Wi-Fi 7 mesh router system. The device fails to properly validate input in certain UDP packets, so an attacker who can reach the router over the local network — an adjacent Wi-Fi client, a compromised smart plug, or any other device already inside the home network — can inject shell metacharacters and execute arbitrary commands with root privileges.

The flaw carries a CVSS v4.0 score of 7.7, rated High. Exploitation needs adjacent network access but no login credentials and no action from the router's owner, which is what pushes the severity up despite the attack not being reachable from the open internet. TP-Link's advisory warns that a successful attack can lead to complete device compromise: unauthorised command execution, changed router settings, and loss of confidentiality, integrity and availability for every device the Deco is routing traffic for.

TP-Link has already published a fix. Firmware version 1.3.5, build 26071712, patches the TDDP module's input handling and is available now through the Deco app or TP-Link's UK support pages.

DetailValue
CVE IDCVE-2026-17176
Affected productDeco BE11000, hardware version 2
Vulnerability typeOS command injection (TDDP module, malformed UDP packet)
CVSS v4.0 score7.7 — High
Disclosed10 September 2026
Fixed firmware1.3.5, build 26071712

Why does this matter for Home Assistant users?

It matters because a mesh router like the Deco BE11000 usually sits at the centre of a smart home network, not at its edge. Anyone running Home Assistant alongside a Deco system is trusting that router to keep every Zigbee coordinator, Wi-Fi camera and voice assistant on the LAN isolated from anything that shouldn't be there. Root access to the router undermines that trust in one step: an attacker with root on the Deco can see and redirect traffic between every device on the network, including any Home Assistant instance, NAS box or smart lock bridge connected to it.

This is also a reminder that "local control" is not automatically "safe" — a device only stays trustworthy if its firmware is patched. Home Assistant's own security model assumes the local network is a reasonably safe perimeter; a compromised router breaks that assumption for every integration running on it, cloud-connected or not. Anyone who segments IoT devices onto a separate VLAN, as our own VLAN guide recommends, has some extra protection here, since an attacker would still need to reach the Deco's management interface from the IoT segment specifically — but VLANs don't replace patching the router itself.

How do I update my Deco BE11000 firmware?

Open the Deco app, go to MoreFirmware Upgrade, and check whether your unit is already on 1.3.5, build 26071712, or newer. If not, tap Upgrade and let every node in the mesh update — TP-Link pushes the fix to all satellite units, not just the primary router. The update can also be triggered from the web interface at the router's local IP address for anyone who prefers not to use the app. TP-Link's advisory doesn't list a manual workaround short of updating, so there's no reason to delay once the update is available.

Should you replace your Deco or wait it out?

There's no need to replace the hardware. TP-Link responded with a firmware fix rather than a recall, which is the normal outcome for a router-firmware vulnerability like this one — the same pattern played out with the Deco BE25's command injection and path traversal flaws disclosed earlier in 2026. The practical response is simply to update promptly and to keep automatic firmware updates switched on in the Deco app afterwards, since router vendors routinely find and patch TDDP-style issues after release. If you're shopping for a mesh system today rather than patching one you already own, our TP-Link Deco review covers how the current line-up compares on performance and price, and our home network security guide covers the wider steps worth taking regardless of which router brand you use.

Frequently asked questions

Is the TP-Link Deco BE11000 vulnerability exploitable over the internet?
No — CVE-2026-17176 requires adjacent network access, meaning an attacker needs to already be on the same local network as the Deco BE11000, either as a Wi-Fi client or via another compromised device on that network. It isn't remotely exploitable from the open internet the way some router flaws are. That doesn't make it low-risk: it needs no login credentials and no action from the router's owner, so any already-compromised smart device, a malicious guest-network user, or an attacker who has cracked the Wi-Fi password can trigger it. TP-Link rates it CVSS 7.7, High, and has released fixed firmware (1.3.5, build 26071712), so the practical fix is the same regardless of the attack path: update promptly rather than relying on the network boundary alone.
How do I check if my Deco BE11000 firmware is already patched?
Open the Deco app, tap More, then Firmware Upgrade, and check the version shown against your router's satellite units. TP-Link's fix for CVE-2026-17176 shipped as firmware 1.3.5, build 26071712 — if your unit already shows that version or newer, it's patched; if it shows an older build, tap Upgrade and wait for every node in the mesh to update, not just the primary unit. You can also check from the web interface at the router's local IP address if you'd rather not use the app. TP-Link's advisory lists no workaround other than updating, so there's no configuration change that substitutes for installing the fix.

Sources

Sources verified 2026-09-12

  1. TP-Link — Security Advisory: OS command injection Vulnerability in Deco BE11000 (CVE-2026-17176)
  2. TP-Link — Security Advisory on Command Injection and Path Traversal Vulnerabilities on TP-Link Deco BE25
How we researched this

Claims in this article are checked against primary sources — manufacturer specifications, official documentation, Which? research, Ofgem guidance, or gov.uk — rather than forum threads or video reviews. Where the author has direct hands-on experience with a product (most Home Assistant, Zigbee, and home-networking gear is running in his own homelab), that is stated explicitly in the text.

For categories outside that personal setup — such as boilers, heat pumps, and other areas that are traditionally a heating engineer's domain — verdicts are built from cross-referenced manufacturer data, published lab results, and vetted expert and owner reviews rather than a claim of personal hands-on testing. See the editorial policy for the full methodology.

Sepehr

Written by

Sepehr

10+ years hands-on with Home Assistant & networking · Research-backed elsewhere · No brand deals

Smart home specialist with 10+ years running a self-hosted Home Assistant setup — Zigbee2MQTT, Frigate NVR, and local-first automations. Independent coverage for UK homes, no brand deals.

LinkedIn →

Citing this page? Please use a dofollow link back to the original article — it helps us keep the data on this page accurate and up to date.

Related reading