OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-8618

HIGH · CVSS 7.7 EPSS 0.23% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-10-01 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

A stack-based buffer overflow vulnerability in the TDDPv2 service on Deco M9 Plus devices can be exploited due to inadequate validation of decrypted request data length, leading to potential denial of service or arbitrary code execution. This issue primarily affects devices during the setup phase and poses a significant risk to users in environments where adjacent attackers could send crafted TDDP packets. Organizations using Deco M9 Plus devices should prioritize patching to mitigate the risk of exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit arbitrary code execution code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-8618
Severity
HIGH
CVSS
7.7
EPSS
0.23%

Original NVD Description

A stack-based buffer overflow vulnerability exists in the TDDPv2 service (/usr/bin/tddp) on Deco M9 Plus due to insufficient validation of decrypted request data length before it is copied into a fixed-size stack buffer in the subtype 0x91 handler. Successful exploitation may allow an adjacent, unauthenticated attacker to cause a denial of service or achieve arbitrary code execution during the device setup phase through crafted TDDP packets.