← Back to CVE List
CVE-2026-8618NVD
Vulnerability Summary
A stack-based buffer overflow vulnerability exists in the TDDPv2 service (/usr/bin/tddp) on Deco M9 Plus due to insufficient validation of decrypted request data length before it is copied into a fixed-size stack buffer in the subtype 0x91 handler. Successful exploitation may allow an adjacent, unauthenticated attacker to cause a denial of service or achieve arbitrary code execution during the device setup phase through crafted TDDP packets.
CVSS v4.0 Base Metrics — Score 7.7 (HIGH)
Attack VectorAdjacent
Attack ComplexityLow
Attack RequirementsPresent
Privileges RequiredNone
User InteractionNone
Confidentiality (Vulnerable System)High
Integrity (Vulnerable System)High
Availability (Vulnerable System)High
Confidentiality (Subsequent System)Low
Integrity (Subsequent System)Low
Availability (Subsequent System)Low
Affected & Patched Versions
- TP-Link Systems Inc. Deco M9 Plus V2 < 1.9.2 Build 20260818
- TP-Link Systems Inc. Deco M9 Plus V2 1.9.2 Build 20260818