Skip to finding
important · Wi-Fi

An unauthenticated LAN packet can exploit a stack overflow for code execution on a Deco M9 Plus during setup.

Affects

TP-Link Deco M9 Plus V2, an embedded whole-home mesh Wi-Fi router.

The attacker needs adjacent-network packet delivery to a Deco M9 Plus V2 while it is in its setup phase.

Detail and 2 sources

Attacker-controlled TDDPv2 subtype 0x91 data overflows a fixed-size stack buffer and permits code execution.

The exposure is limited to one older hardware revision during setup; TP-Link published corrected firmware, but the fix was not read for this brief.

Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Saturday, October 3, 2026