CVE-2026-15469
Gravedad CVSS v4.0:
ALTA
Tipo:
CWE-321
Uso de claves de cifrado embebidas en el software
Fecha de publicación:
24/08/2026
Última modificación:
24/08/2026
Descripción
*** Pendiente de traducción *** The use of<br />
hard-coded cryptographic key vulnerability has been identified in the mesh<br />
functionality of Deco XE75 v3, XE5300 v3.6 and WE10800 v3.6. <br />
A shared RSA-512 mesh group private key is present in the affected<br />
firmware and is used by the mesh protocol for node authentication. An attacker who obtains the firmware image<br />
and has local network access may be able to authenticate as a mesh node without<br />
possessing a device-specific credential.<br />
<br />
<br />
<br />
<br />
<br />
Successful<br />
exploitation may allow an unauthenticated adjacent attacker to impersonate a<br />
trusted mesh node and bypass mesh node authentication, which may permit unauthorized<br />
changes to device or mesh configuration, affecting confidentiality, integrity<br />
and availability.
Impacto
Puntuación base 4.0
7.70
Gravedad 4.0
ALTA
Referencias a soluciones, herramientas e información
- https://www.tp-link.com/en/support/download/deco-xe75/v3.60/#Firmware
- https://www.tp-link.com/us/support/download/deco-we10800/#Firmware
- https://www.tp-link.com/us/support/download/deco-xe5300/#Firmware
- https://www.tp-link.com/us/support/download/deco-xe75/v3.60/#Firmware
- https://www.tp-link.com/us/support/faq/5263/



