VYPR

Deco M9 Plus

by TP-Link

CVEs (2)

  • CVE-2026-8618HigOct 1, 2026
    risk 0.50cvss —epss —

    A stack-based buffer overflow vulnerability exists in the TDDPv2 service (/usr/bin/tddp) on Deco M9 Plus due to insufficient validation of decrypted request data length before it is copied into a fixed-size stack buffer in the subtype 0x91 handler. Successful exploitation may…

  • CVE-2026-17176HigSep 11, 2026
    risk 0.50cvss —epss 0.04

    An OS command injection vulnerability in the TDDP module of Deco BE11000 and Deco M9 Plus allows an adjacent network attacker to execute arbitrary commands with root privileges by sending a crafted UDP packet. Successful exploitation may lead to complete device compromise,…