CVE-2026-8618: TP-Link Systems Inc Deco m9 Plus v2
High severity, CVSS 7.7. EPSS: 0.2% chance of exploitation in the next 30 days.
A stack-based buffer overflow vulnerability exists in the TDDPv2 service (/usr/bin/tddp) on Deco M9 Plus due to insufficient validation of decrypted request data length before it is copied into a fixed-size stack buffer in the subtype 0x91 handler. Successful exploitation may allow an adjacent, unauthenticated attacker to cause a denial of service or achieve arbitrary code execution during the device setup phase through crafted TDDP packets.
Affected products
- TP-Link Systems Inc Deco m9 Plus v2: before 1.9.2 Build 20260818 (fixed in 1.9.2 Build 20260818)
Published 2026-10-01. Last modified 2026-10-01.