{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2026-15469",
        "assignerOrgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
        "state": "PUBLISHED",
        "assignerShortName": "TPLink",
        "dateReserved": "2026-07-10T22:04:23.852Z",
        "datePublished": "2026-08-24T16:32:12.573Z",
        "dateUpdated": "2026-08-24T17:25:22.871Z"
    },
    "containers": {
        "cna": {
            "providerMetadata": {
                "orgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
                "shortName": "TPLink",
                "dateUpdated": "2026-08-24T16:32:12.573Z"
            },
            "title": "Hard-coded Mesh Group Private Key in TP-Link Deco XE75, XE5300, and WE10800",
            "problemTypes": [
                {
                    "descriptions": [
                        {
                            "lang": "en",
                            "cweId": "CWE-321",
                            "description": "CWE-321 Use of hard-coded cryptographic key",
                            "type": "CWE"
                        }
                    ]
                }
            ],
            "impacts": [
                {
                    "capecId": "CAPEC-115",
                    "descriptions": [
                        {
                            "lang": "en",
                            "value": "CAPEC-115 Authentication Bypass"
                        }
                    ]
                }
            ],
            "affected": [
                {
                    "vendor": "TP-Link Systems Inc.",
                    "product": "Deco XE75 v3 / XE5300  v3.6/ WE10800 v3.6",
                    "modules": [
                        "mesh"
                    ],
                    "versions": [
                        {
                            "status": "affected",
                            "version": "0",
                            "lessThan": "1.5.0 Build 20260603",
                            "versionType": "custom"
                        }
                    ],
                    "defaultStatus": "unaffected"
                }
            ],
            "descriptions": [
                {
                    "lang": "en",
                    "value": "The use of\nhard-coded cryptographic key vulnerability has been identified in the mesh\nfunctionality of Deco XE75 v3, XE5300 v3.6 and WE10800 v3.6. \nA shared RSA-512 mesh group private key is present in the affected\nfirmware and is used by the mesh protocol for node authentication.  An attacker who obtains the firmware image\nand has local network access may be able to authenticate as a mesh node without\npossessing a device-specific credential.\n\n\n\n\n\nSuccessful\nexploitation may allow an unauthenticated adjacent attacker to impersonate a\ntrusted mesh node and bypass mesh node authentication, which may permit unauthorized\nchanges to device or mesh configuration, affecting confidentiality, integrity\nand availability.",
                    "supportingMedia": [
                        {
                            "type": "text/html",
                            "base64": false,
                            "value": "<p>The use of\nhard-coded cryptographic key vulnerability has been identified in the mesh\nfunctionality of Deco XE75 v3, XE5300 v3.6 and WE10800 v3.6.&nbsp;\nA shared RSA-512 mesh group private key is present in the affected\nfirmware and is used by the mesh protocol for node authentication.&nbsp; An attacker who obtains the firmware image\nand has local network access may be able to authenticate as a mesh node without\npossessing a device-specific credential.</p>\n\n<p>Successful\nexploitation may allow an unauthenticated adjacent attacker to impersonate a\ntrusted mesh node and bypass mesh node authentication, which may permit unauthorized\nchanges to device or mesh configuration, affecting confidentiality, integrity\nand availability.</p>"
                        }
                    ]
                }
            ],
            "references": [
                {
                    "url": "https://www.tp-link.com/us/support/download/deco-xe75/v3.60/#Firmware",
                    "tags": [
                        "patch"
                    ]
                },
                {
                    "url": "https://www.tp-link.com/en/support/download/deco-xe75/v3.60/#Firmware",
                    "tags": [
                        "patch"
                    ]
                },
                {
                    "url": "https://www.tp-link.com/us/support/download/deco-xe5300/#Firmware",
                    "tags": [
                        "patch"
                    ]
                },
                {
                    "url": "https://www.tp-link.com/us/support/download/deco-we10800/#Firmware",
                    "tags": [
                        "patch"
                    ]
                },
                {
                    "url": "https://www.tp-link.com/us/support/faq/5263/",
                    "tags": [
                        "vendor-advisory"
                    ]
                }
            ],
            "metrics": [
                {
                    "format": "CVSS",
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "GENERAL"
                        }
                    ],
                    "cvssV4_0": {
                        "attackVector": "ADJACENT",
                        "attackComplexity": "LOW",
                        "attackRequirements": "PRESENT",
                        "privilegesRequired": "NONE",
                        "userInteraction": "NONE",
                        "vulnConfidentialityImpact": "HIGH",
                        "subConfidentialityImpact": "LOW",
                        "vulnIntegrityImpact": "HIGH",
                        "subIntegrityImpact": "LOW",
                        "vulnAvailabilityImpact": "HIGH",
                        "subAvailabilityImpact": "LOW",
                        "exploitMaturity": "NOT_DEFINED",
                        "Safety": "NOT_DEFINED",
                        "Automatable": "NOT_DEFINED",
                        "Recovery": "NOT_DEFINED",
                        "valueDensity": "NOT_DEFINED",
                        "vulnerabilityResponseEffort": "NOT_DEFINED",
                        "providerUrgency": "NOT_DEFINED",
                        "version": "4.0",
                        "baseSeverity": "HIGH",
                        "baseScore": 7.7,
                        "vectorString": "CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L"
                    }
                }
            ],
            "source": {
                "discovery": "UNKNOWN"
            },
            "x_generator": {
                "engine": "Vulnogram 1.0.2"
            }
        },
        "adp": [
            {
                "metrics": [
                    {
                        "other": {
                            "type": "ssvc",
                            "content": {
                                "timestamp": "2026-08-24T17:25:18.245788Z",
                                "id": "CVE-2026-15469",
                                "options": [
                                    {
                                        "Exploitation": "none"
                                    },
                                    {
                                        "Automatable": "no"
                                    },
                                    {
                                        "Technical Impact": "total"
                                    }
                                ],
                                "role": "CISA Coordinator",
                                "version": "2.0.3"
                            }
                        }
                    }
                ],
                "title": "CISA ADP Vulnrichment",
                "providerMetadata": {
                    "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
                    "shortName": "CISA-ADP",
                    "dateUpdated": "2026-08-24T17:25:22.871Z"
                }
            }
        ]
    }
}