Impact
TP‑Link Deco M5 v1 routers store user credentials using a weak password hashing mechanism, which allows an attacker who can obtain a password hash to perform brute‑force or dictionary attacks. When successful, the attacker can gain access to authentication credentials and potentially control device management functions, resulting in loss of confidentiality.
Affected Systems
The vulnerability affects TP‑Link Deco M5 routers running firmware version v1. Only devices identified as TP‑Link Deco M5 v1 are known to be impacted.
Risk and Exploitability
The CVSS score of 7.1 indicates a high impact if exploited. The EPSS score of less than 1% shows that the likelihood of exploitation is low but not negligible, and the vulnerability is not listed in CISA KEV. An attacker would first need to acquire the password hash through a system compromise or privileged access; once the hash is known, they can launch offline hash‑cracking attempts to obtain the plaintext password and gain unauthorized management access.
OpenCVE Enrichment