High severityNVD Advisory· Published Oct 1, 2026· Updated Oct 1, 2026
CVE-2026-8618
CVE-2026-8618
Description
A stack-based buffer overflow vulnerability exists in the TDDPv2 service (/usr/bin/tddp) on Deco M9 Plus due to insufficient validation of decrypted request data length before it is copied into a fixed-size stack buffer in the subtype 0x91 handler. Successful exploitation may allow an adjacent, unauthenticated attacker to cause a denial of service or achieve arbitrary code execution during the device setup phase through crafted TDDP packets.
Affected products
1Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.