CVE-2026-5040
Awaiting Analysis Awaiting Analysis - Queue

Weak Password Hashing in TP-Link Deco M5 v1

Vulnerability report for CVE-2026-5040, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-14

Last updated on: 2026-07-15

Assigner: TPLink

Description

TP-Link Deco M5 v1 uses a weak password hashing mechanism to store user credentials. An attacker who obtains the password hash through system compromise or privileged access could perform brute-force or dictionary attacks. Successful exploitation may result in disclosure of authentication credentials, enabling unauthorized access to device management functions, depending on the privileges associated with the recovered password. The primary security impact is loss of confidentiality.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-14
Last Modified
2026-07-15
Generated
2026-08-04
AI Q&A
2026-07-15
EPSS Evaluated
2026-08-02
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
tp-link deco_m5 to 1.9.4_build_20260312 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-916 The product generates a hash for a password, but it uses a scheme that does not provide a sufficient level of computational effort that would make password cracking attacks infeasible or expensive.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

TP-Link Deco M5 v1 uses a weak password hashing mechanism to store user credentials. An attacker with access to password hashes could perform brute-force or dictionary attacks to recover authentication credentials. This could lead to unauthorized access to device management functions if the compromised account has sufficient privileges.

Detection Guidance

Detection involves checking if your TP-Link Deco M5 v1 is running vulnerable firmware. Verify the firmware version via the device admin panel or TP-Link Tapo app. If the version is below 1.9.4 Build 20260312 Rel.17129, the device is vulnerable. Network scanning tools like Nmap can identify Deco M5 devices but cannot directly detect the weak hashing flaw.

Impact Analysis

This vulnerability may result in disclosure of authentication credentials, allowing unauthorized access to device management functions. The impact depends on the privileges of the compromised account. The primary security impact is loss of confidentiality.

Mitigation Strategies

Immediately update the firmware to version 1.9.4 Build 20260312 or later via the official TP-Link website. Ensure a wired connection during the update and avoid power interruptions. After updating, change all device passwords to strong, unique values to prevent brute-force attacks.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-5040. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart