CVE-2026-15469
Received Received - Intake

Hard-Coded RSA-512 Key in Deco XE Series

Vulnerability report for CVE-2026-15469, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-24

Last updated on: 2026-08-24

Assigner: TPLink

Description

The use of hard-coded cryptographic key vulnerability has been identified in the mesh functionality of Deco XE75 v3, XE5300 v3.6 and WE10800 v3.6.Β  A shared RSA-512 mesh group private key is present in the affected firmware and is used by the mesh protocol for node authentication.Β  An attacker who obtains the firmware image and has local network access may be able to authenticate as a mesh node without possessing a device-specific credential. Successful exploitation may allow an unauthenticated adjacent attacker to impersonate a trusted mesh node and bypass mesh node authentication, which may permit unauthorized changes to device or mesh configuration, affecting confidentiality, integrity and availability.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-24
Last Modified
2026-08-24
Generated
2026-08-24
AI Q&A
2026-08-24
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 9 associated CPEs
Vendor Product Version / Range
deco xe75 3
deco xe5300 3.6
deco we10800 3.6
tp-link deco_xe75 1.5.0_build_20260603_rel.14401
tp-link deco_xe5300 1.5.0_build_20260603_rel.14401
tp-link deco_we10800 1.5.0_build_20260603_rel.14401
tp-link deco_xe75 3.60
tp-link deco_xe5300 to 1.5.0 (inc)
tp-link deco_we10800 to 1.5.0 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-321 The product uses a hard-coded, unchangeable cryptographic key.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves a hard-coded RSA-512 cryptographic key in the mesh functionality of TP-Link Deco XE75 v3, XE5300 v3.6, and WE10800 v3.6 firmware. The shared private key is used for mesh node authentication, allowing an attacker with local network access to impersonate a trusted node without valid credentials.

Detection Guidance

Detection requires checking firmware versions on affected devices (Deco XE75 v3, XE5300 v3.6, WE10800 v3.6). Compare installed firmware against TP-Link's fixed version (1.5.0 Build 20260603 Rel.14401). Use device admin panel or SSH to verify firmware. Monitor network traffic for unauthorized mesh node authentication attempts.

Impact Analysis

An attacker could bypass authentication, impersonate mesh nodes, and make unauthorized changes to device or mesh configurations. This may lead to loss of confidentiality, integrity, and availability of your network and connected devices.

Compliance Impact

This vulnerability could lead to unauthorized access and configuration changes, potentially violating data protection requirements under GDPR and HIPAA by compromising confidentiality, integrity, and availability of sensitive data.

Mitigation Strategies

Immediately update all affected devices to firmware version 1.5.0 Build 20260603 Rel.14401 or later. Disable mesh functionality if updates cannot be applied promptly. Restrict local network access to trusted devices only. Monitor device configurations for unauthorized changes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-15469. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart