{"id":"CVE-2026-15469","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-15469","summary":"The use of\nhard-coded cryptographic key vulnerability has been identified in the mesh\nfunctionality of Deco XE75 v3, XE5300 v3.6 and WE10800 v3.6. \nA shared RSA-512 mesh group private…","details":"The use of\nhard-coded cryptographic key vulnerability has been identified in the mesh\nfunctionality of Deco XE75 v3, XE5300 v3.6 and WE10800 v3.6. \nA shared RSA-512 mesh group private key is present in the affected\nfirmware and is used by the mesh protocol for node authentication.  An attacker who obtains the firmware image\nand has local network access may be able to authenticate as a mesh node without\npossessing a device-specific credential.\n\n\n\n\n\nSuccessful\nexploitation may allow an unauthenticated adjacent attacker to impersonate a\ntrusted mesh node and bypass mesh node authentication, which may permit unauthorized\nchanges to device or mesh configuration, affecting confidentiality, integrity\nand availability.","published":"2026-08-24T17:17:21.587","modified":"2026-08-24T17:17:21.587","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://www.tp-link.com/en/support/download/deco-xe75/v3.60/#Firmware"},{"type":"WEB","url":"https://www.tp-link.com/us/support/download/deco-we10800/#Firmware"},{"type":"WEB","url":"https://www.tp-link.com/us/support/download/deco-xe5300/#Firmware"},{"type":"WEB","url":"https://www.tp-link.com/us/support/download/deco-xe75/v3.60/#Firmware"},{"type":"WEB","url":"https://www.tp-link.com/us/support/faq/5263/"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-08-24T17:17:21.587"}}