Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2025-32107

CVE-2025-32107: Deco BE65 Pro RCE Vulnerability

CVE-2025-32107 is a command injection vulnerability in TP-Link Deco BE65 Pro routers that enables authenticated attackers to execute arbitrary OS commands. This article covers technical details, affected firmware versions, and mitigation.

Published:

CVE-2025-32107 Overview

CVE-2025-32107 is an operating system (OS) command injection vulnerability [CWE-78] affecting TP-Link Deco BE65 Pro mesh Wi-Fi routers. The flaw exists in firmware versions prior to Deco BE65 Pro(JP)_V1_1.1.2 Build 20250123. An authenticated attacker on an adjacent network can inject arbitrary operating system commands that execute on the device.

Successful exploitation grants command execution in the context of the router's underlying OS. This enables persistent network compromise, traffic interception, and pivoting to internal hosts.

Critical Impact

An authenticated user on the adjacent network can execute arbitrary OS commands on the router, resulting in high confidentiality, integrity, and availability impact.

Affected Products

  • TP-Link Deco BE65 Pro firmware versions prior to Deco BE65 Pro(JP)_V1_1.1.2 Build 20250123
  • Japanese regional firmware branch of the Deco BE65 Pro mesh Wi-Fi 7 router
  • Devices administered by an authenticated local user with login access

Discovery Timeline

  • 2025-04-11 - CVE-2025-32107 published to the National Vulnerability Database (NVD)
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2025-32107

Vulnerability Analysis

The vulnerability is classified under CWE-78, Improper Neutralization of Special Elements used in an OS Command. Attacker-controlled input reaches an OS command interpreter on the router without sufficient sanitization or escaping.

Exploitation requires authenticated access to the device management interface and adjacent network positioning. This means the attacker must be on the local Wi-Fi or LAN segment, not the public internet. The scope remains unchanged, and the attacker gains full read, write, and disruption capability on the affected router.

Because routers sit inline with all client traffic, command execution on the device permits DNS redirection, credential harvesting through captive portals, and lateral movement to internal systems.

Root Cause

The root cause is missing or inadequate input validation in a management-plane handler that constructs an OS shell command from user-supplied parameters. Metacharacters such as ;, |, &, and backticks are not neutralized before being passed to the command interpreter. The affected code path is reachable by any user who can authenticate to the device.

Attack Vector

An attacker first joins the adjacent network and authenticates to the Deco BE65 Pro management interface using valid credentials. The attacker then submits a crafted request to a vulnerable endpoint, embedding shell metacharacters and additional commands within a parameter value. The router concatenates the tainted input into a system call, and the injected commands execute with the privileges of the router's management process.

Detailed reproduction steps have not been published. Consult the JVN Vulnerability Report for coordinated disclosure information.

Detection Methods for CVE-2025-32107

Indicators of Compromise

  • Unexpected outbound connections initiated by the router to unknown IP addresses or domains
  • Unauthorized changes to DNS servers, firewall rules, port forwarding, or administrative accounts in the Deco management console
  • Router configuration or firmware version that does not match the deployed baseline
  • Repeated authenticated administrative sessions from unfamiliar client MAC addresses or IP addresses

Detection Strategies

  • Compare the running firmware version against Deco BE65 Pro(JP)_V1_1.1.2 Build 20250123 and flag any device running an earlier build
  • Inspect router administrative logs for command parameters containing shell metacharacters such as ;, |, &, $(, or backticks
  • Correlate authentication events on the Deco management interface with subsequent anomalous outbound router traffic

Monitoring Recommendations

  • Forward router syslog and administrative event data to a centralized log platform for retention and query
  • Alert on firmware downgrades, factory resets, and configuration changes performed outside approved maintenance windows
  • Monitor the adjacent wireless and wired segments for unauthorized clients that reach the router's management interface

How to Mitigate CVE-2025-32107

Immediate Actions Required

  • Upgrade affected Deco BE65 Pro devices to firmware Deco BE65 Pro(JP)_V1_1.1.2 Build 20250123 or later, available from the TP-Link Deco BE65 Pro Firmware download page
  • Rotate all administrative credentials on the router after patching
  • Review router configuration, DNS settings, port forwarding rules, and administrative accounts for unauthorized changes
  • Restrict management interface access to a dedicated management VLAN or trusted client list

Patch Information

TP-Link has released fixed firmware. Apply Deco BE65 Pro(JP)_V1_1.1.2 Build 20250123 or later. Refer to the JVN Vulnerability Report and the TP-Link firmware portal for regional builds and installation guidance.

Workarounds

  • Disable remote management and limit administrative access to trusted local clients until the firmware update is applied
  • Enforce strong, unique administrator passwords and multi-factor authentication where supported to raise the barrier for the authenticated attack precondition
  • Segment IoT and guest devices onto isolated SSIDs and VLANs so untrusted clients cannot reach the router's management plane

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.