PT-2026-80926 · Tp Link · Deco Xe75+2

·

CVE-2026-15469

·

Published

2026-07-20

·

Updated

2026-08-24

CVSS v2.0

8.3

High

VectorAV:A/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Deco XE75 v3 XE5300 v3.6 WE10800 v3.6
Description The mesh functionality contains a hard-coded shared RSA-512 mesh group private key used by the mesh protocol for node authentication. An unauthenticated attacker with local network access and the firmware image can use this key to impersonate a trusted mesh node and bypass authentication. This may lead to unauthorized changes to the device or mesh configuration, impacting confidentiality, integrity, and availability.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-13470
CVE-2026-15469

Affected Products

Deco Xe75
We10800
Xe5300