CVE-2026-8618: Pre-Authentication Stack-based Buffer Overflow Remote Code Execution in TDDPv2 Subtype 0x91 on Deco M9 Plus

Published Oct 1, 2026
·
Updated

A stack-based buffer overflow vulnerability exists in the TDDPv2 service (/usr/bin/tddp) on Deco M9 Plus due to insufficient validation of decrypted request data length before it is copied into a fixed-size stack buffer in the subtype 0x91 handler. Successful exploitation may allow an adjacent, unauthenticated attacker to cause a denial of service or achieve arbitrary code execution during the device setup phase through crafted TDDP packets.

Affected Software

1 affected component
TP-Link Deco M9 Plus

Event History

Oct 1, 2026
CVE Published
via MITRE·06:16 PM
Data Sourced
via MITRE·06:16 PM
DescriptionWeakness
Data Sourced
via NVD·07:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An attacker must be adjacent to the Deco M9 Plus and able to send crafted TDDP packets to the device. Authentication is not required.

2

When is the device exposed?

The vulnerable subtype 0x91 handler is reachable during the device setup phase. The provided information does not establish exposure outside that phase.

3

What impact can successful exploitation have?

Successful exploitation may allow denial of service or arbitrary code execution on the affected device.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203