CVE-2026-8618

HIGH CVSS 4.0: 7.7 EPSS 0.23%
Updated Oct 01, 2026
Tp-Link Systems Inc.
Parameter Value
CVSS 7.7 (HIGH)
Type CWE-121 (Stack-based Buffer Overflow)
Vendor Tp-Link Systems Inc.
Public PoC No

A stack-based buffer overflow vulnerability exists in the TDDPv2 service (/usr/bin/tddp) on Deco M9 Plus due to insufficient validation of decrypted request data length before it is copied into a fixed-size stack buffer in the subtype 0x91 handler. Successful exploitation may allow an adjacent, unauthenticated attacker to cause a denial of service or achieve arbitrary code execution during the device setup phase through crafted TDDP packets.

Attack Parameters

Attack Vector
Adjacent
Requires local network access
Attack Complexity
Low
Easy to exploit
Attack Requirements
Present
Additional conditions required
Privileges Required
None
No privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
High
Complete data modification
Availability
High
Complete denial of service

CVSS Vector v4.0

Vulnerable Products

tp-link systems inc.:deco m9 plus v2