Impact
The vulnerability stems from a hard‑coded RSA‑512 mesh‑group private key embedded in the firmware of certain TP‑Link Deco routers. This key is used for authenticating nodes within the mesh network. An attacker who can acquire the firmware image and gain local network access can impersonate a legitimate mesh node. By doing so, the attacker may bypass authentication checks and perform unauthorized changes to device or mesh configuration, thereby compromising confidentiality, integrity and availability of the network. The weakness is identified as CWE‑321, which addresses improper key management.
Affected Systems
TP‑Link Systems Inc. – Deco XE75 v3 (firmware 3.60), Deco XE5300 v3.6 (firmware 3.60), and Deco WE10800 v3.6 (firmware 3.60) are affected. The issue is confined to the mesh functionality of these devices and is linked to the specific firmware versions mentioned.
Risk and Exploitability
The CVSS score of 7.7 classifies the flaw as high severity. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. An attacker with local network proximity and possession of the firmware image can exploit the vulnerability; the attack requires physical or local network presence but does not need remote host access. The malicious actor could then impersonate a legitimate mesh node and alter configuration settings, potentially leading to a compromised network infrastructure.
OpenCVE Enrichment