important · Wi-Fi
An unauthenticated LAN packet can exploit a stack overflow for code execution on a Deco M9 Plus during setup.
Affects
TP-Link Deco M9 Plus V2, an embedded whole-home mesh Wi-Fi router.
The attacker needs adjacent-network packet delivery to a Deco M9 Plus V2 while it is in its setup phase.
Detail and 2 sources
Attacker-controlled TDDPv2 subtype 0x91 data overflows a fixed-size stack buffer and permits code execution.
The exposure is limited to one older hardware revision during setup; TP-Link published corrected firmware, but the fix was not read for this brief.