Tp Link · Deco Xe75 · CVE-2026-15469
**Name of the Vulnerable Software and Affected Versions**
Deco XE75 v3
XE5300 v3.6
WE10800 v3.6
**Description**
The mesh functionality contains a hard-coded shared RSA-512 mesh group private key used by the mesh protocol for node authentication. An unauthenticated attacker with local network access and the firmware image can use this key to impersonate a trusted mesh node and bypass authentication. This may lead to unauthorized changes to the device or mesh configuration, impacting confidentiality, integrity, and availability.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.