PT-2026-80926 · Tp Link · Deco Xe75+2
CVSS v2.0
8.3
High
| Vector | AV:A/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Deco XE75 v3
XE5300 v3.6
WE10800 v3.6
Description
The mesh functionality contains a hard-coded shared RSA-512 mesh group private key used by the mesh protocol for node authentication. An unauthenticated attacker with local network access and the firmware image can use this key to impersonate a trusted mesh node and bypass authentication. This may lead to unauthorized changes to the device or mesh configuration, impacting confidentiality, integrity, and availability.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Deco Xe75
We10800
Xe5300