Deco M9 Plus 设备上的 TDDPv2 服务(/usr/bin/tddp)中存在一个基于栈的缓冲区溢出漏洞。该漏洞源于在将解密后的请求数据复制到固定大小的栈缓冲区之前,未对数据长度进行充分验证(具体发生在子类型 0x91 的处理程序中)。成功利用此漏洞可能允许相邻的未认证攻击者通过构造恶意的 TDDP 数据包,在设备配置阶段触发拒绝服务(DoS)或实现任意代码执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| TP-Link Systems Inc. | Deco M9 Plus V2 | 0 ~ 1.9.2 Build 20260818 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-102369 | 8.7 HIGH | Unauthenticated Remote Code Execution via MacTool Command Injection in TP-Link Tapo C120 & |
| CVE-2026-84682 | 7.7 HIGH | TDDPv2 setProductVer Command Injection in Archer AX90 |
| CVE-2026-9032 | 7.1 HIGH | Unauthenticated Onboarding Connect NULL Pointer Dereference Denial of Service Vulnerabilit |
| CVE-2026-78578 | 7.1 HIGH | Unauthenticated do Method Onboarding Connect Allows Wi‑Fi Reconfiguration Denial of Servic |
| CVE-2026-78577 | 5.3 MEDIUM | Unauthenticated Onboarding Scan Information Disclosure in TP-Link Tapo C120 & C200 |
No comments yet