CPU core protect during DDoS to do blackhole

Hello, If I receive a DDoS, there is any way to limit the CPU usage for the main uplink to don’t use more than a 90% of CPU and then be available to login to the router and do the blackhole?

My upstream, can provide me a second uplink with other IP, but the main problem, is, if I’m under DDoS and the CPU is 100% the entire router is blocked and I can’t also connect to the rescue interface.

What sort of DDoS are you experiencing? I have never had trouble logging in to the main router to block an IP. Actually we typically log in and drop a BGP route for a minute or two.
I’ve Tried this with 100mbps and 1gbps of small packets to a single IP address.