CVE-2026-15469

Severity CVSS v4.0:
HIGH
Type:
CWE-321 Use of Hard-coded Cryptographic Key
Publication date:
24/08/2026
Last modified:
24/08/2026

Description

The use of<br /> hard-coded cryptographic key vulnerability has been identified in the mesh<br /> functionality of Deco XE75 v3, XE5300 v3.6 and WE10800 v3.6. <br /> A shared RSA-512 mesh group private key is present in the affected<br /> firmware and is used by the mesh protocol for node authentication.  An attacker who obtains the firmware image<br /> and has local network access may be able to authenticate as a mesh node without<br /> possessing a device-specific credential.<br /> <br /> <br /> <br /> <br /> <br /> Successful<br /> exploitation may allow an unauthenticated adjacent attacker to impersonate a<br /> trusted mesh node and bypass mesh node authentication, which may permit unauthorized<br /> changes to device or mesh configuration, affecting confidentiality, integrity<br /> and availability.