Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-15469

Gravedad CVSS v4.0:
ALTA
Tipo:
CWE-321 Uso de claves de cifrado embebidas en el software
Fecha de publicación:
24/08/2026
Última modificación:
24/08/2026

Descripción

*** Pendiente de traducción *** The use of<br /> hard-coded cryptographic key vulnerability has been identified in the mesh<br /> functionality of Deco XE75 v3, XE5300 v3.6 and WE10800 v3.6. <br /> A shared RSA-512 mesh group private key is present in the affected<br /> firmware and is used by the mesh protocol for node authentication.  An attacker who obtains the firmware image<br /> and has local network access may be able to authenticate as a mesh node without<br /> possessing a device-specific credential.<br /> <br /> <br /> <br /> <br /> <br /> Successful<br /> exploitation may allow an unauthenticated adjacent attacker to impersonate a<br /> trusted mesh node and bypass mesh node authentication, which may permit unauthorized<br /> changes to device or mesh configuration, affecting confidentiality, integrity<br /> and availability.