CVE-2026-0655 identifies a Path Traversal vulnerability (CWE-22) in TP-Link Deco BE25 v1.0 web modules, impacting firmware up to version 1.1.1 Build 20250822. Rated 8.0 High, an authenticated adjacent attacker with low privileges can exploit this with low complexity to read arbitrary files or cause a denial of service. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion or media coverage for this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.1.1CPE matchmatch criteria | cpe:2.3:o:tp-link:deco_be25_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.