Description
TP-Link Deco M5 v1 uses a weak password hashing mechanism to store user credentials. An attacker who obtains the password hash through system compromise or privileged access could perform brute-force or dictionary attacks.

Successful exploitation may result in disclosure of authentication credentials, enabling unauthorized access to device management functions, depending on the privileges associated with the recovered password. The primary security impact is loss of confidentiality.
Published: 2026-07-14
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

TP‑Link Deco M5 v1 routers store user credentials using a weak password hashing mechanism, which allows an attacker who can obtain a password hash to perform brute‑force or dictionary attacks. When successful, the attacker can gain access to authentication credentials and potentially control device management functions, resulting in loss of confidentiality.

Affected Systems

The vulnerability affects TP‑Link Deco M5 routers running firmware version v1. Only devices identified as TP‑Link Deco M5 v1 are known to be impacted.

Risk and Exploitability

The CVSS score of 7.1 indicates a high impact if exploited. The EPSS score of less than 1% shows that the likelihood of exploitation is low but not negligible, and the vulnerability is not listed in CISA KEV. An attacker would first need to acquire the password hash through a system compromise or privileged access; once the hash is known, they can launch offline hash‑cracking attempts to obtain the plaintext password and gain unauthorized management access.

Generated by OpenCVE AI on July 31, 2026 at 05:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Download and install the latest firmware for Deco M5 v1 from TP‑Link’s official site, and verify if the update includes a fix for the weak hashing mechanism.
  • Change all administrator passwords to unique, complex passwords and avoid using default credentials.
  • Disable remote management or restrict external access to device management interfaces.

Generated by OpenCVE AI on July 31, 2026 at 05:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Tp-link
Tp-link deco M5 Deco M5 V1
Vendors & Products Tp-link
Tp-link deco M5 Deco M5 V1

Wed, 15 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 18:45:00 +0000

Type Values Removed Values Added
Description TP-Link Deco M5 v1 uses a weak password hashing mechanism to store user credentials. An attacker who obtains the password hash through system compromise or privileged access could perform brute-force or dictionary attacks. Successful exploitation may result in disclosure of authentication credentials, enabling unauthorized access to device management functions, depending on the privileges associated with the recovered password. The primary security impact is loss of confidentiality.
Title Weak Password Hashing Mechanism in TP-Link Deco M5
Weaknesses CWE-916
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Tp-link Deco M5 Deco M5 V1
cve-icon MITRE

Status: PUBLISHED

Assigner: TPLink

Published:

Updated: 2026-07-15T10:27:47.808Z

Reserved: 2026-03-27T16:26:49.615Z

Link: CVE-2026-5040

cve-icon Vulnrichment

Updated: 2026-07-15T10:27:42.746Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T06:00:16Z

Weaknesses
  • CWE-916

    Use of Password Hash With Insufficient Computational Effort