CVE-2026-15469
7.7TP-Link · Deco XE75 v3, XE5300 v3.6, WE10800 v3.6
A vulnerability involving the use of hard-coded cryptographic keys in the mesh functionality of several TP-Link Deco models allows attackers to potentially compromise secure communications.
Executive summary
Hard-coded cryptographic keys in the mesh functionality of TP-Link Deco systems expose network traffic to potential decryption and unauthorized access.
Vulnerability
The device uses hard-coded cryptographic keys (CWE-321) within its mesh networking components. This flaw allows an attacker with adjacent network access to potentially bypass security controls or intercept encrypted communications.
Business impact
The use of hard-coded keys fundamentally undermines the encryption protecting the mesh network. If an attacker recovers these keys, they could gain unauthorized access to the network, intercept sensitive data, or perform man-in-the-middle attacks. The CVSS score of 7.7 indicates a high risk to the confidentiality and integrity of the mesh environment.
Remediation
Immediate Action: Update affected Deco units to firmware version 1.5.0 Build 20260603 or the latest available version.
Proactive Monitoring: Monitor network infrastructure for unusual mesh node pairing activity or unauthorized device attempts to join the secure mesh cluster.
Compensating Controls: Ensure all management traffic is segmented from the primary mesh traffic, and employ secondary encryption (such as VPNs) for sensitive data traversing the mesh network.
Exploitation status
Public Exploit Available: No confirmed public exploit (Metasploit or ExploitDB) is currently available.
Analyst recommendation
Hard-coded keys represent a significant architectural weakness that cannot be mitigated by configuration alone. It is imperative that administrators apply the provided firmware update to rotate or remove the vulnerable keys and secure the mesh network.