CVE-2026-8618: Pre-Authentication Stack-based Buffer Overflow Remote Code Execution in TDDPv2 Subtype 0x91 on Deco M9 Plus
A stack-based buffer overflow vulnerability exists in the TDDPv2 service (/usr/bin/tddp) on Deco M9 Plus due to insufficient validation of decrypted request data length before it is copied into a fixed-size stack buffer in the subtype 0x91 handler. Successful exploitation may allow an adjacent, unauthenticated attacker to cause a denial of service or achieve arbitrary code execution during the device setup phase through crafted TDDP packets.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker must be adjacent to the Deco M9 Plus and able to send crafted TDDP packets to the device. Authentication is not required.
When is the device exposed?
The vulnerable subtype 0x91 handler is reachable during the device setup phase. The provided information does not establish exposure outside that phase.
What impact can successful exploitation have?
Successful exploitation may allow denial of service or arbitrary code execution on the affected device.