{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/deco-xe75/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"id":"CVE-2026-15469"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Deco XE75","Deco XE5300","Deco WE10800"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["TP-Link"],"content_html":"\u003cp\u003eTP-Link Deco XE75, XE5300, and WE10800 mesh networking devices contain a hard-coded RSA-512 cryptographic key used for mesh group authentication (TDP/TMP protocols). Because this key is identical across all units of the affected models, an attacker with local network access to the mesh environment can extract the key from publicly available firmware images. Using this key, an attacker can impersonate a legitimate mesh node during the authentication handshake. This vulnerability, tracked as CVE-2026-15469, facilitates critical risks including unauthorized configuration changes, the deployment of unsigned malicious firmware, and seamless lateral movement across the mesh network. The flaw was publicly disclosed following vendor coordination and a patch release. It is fixed in firmware version 1.5.0 Build 20260603 and later.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for the complete compromise of the mesh network environment. Attackers can gain control over configuration settings, inject malicious firmware updates to maintain persistence, and pivot through the network as a trusted mesh node. This affects all deployments of the listed TP-Link Deco models that have not been updated to the corrected firmware version.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate all TP-Link Deco XE75, XE5300, and WE10800 units to firmware version 1.5.0 Build 20260603 or newer immediately.\u003c/li\u003e\n\u003cli\u003eAudit mesh network traffic for unauthorized node onboarding or unusual administrative activity originated from unexpected MAC addresses.\u003c/li\u003e\n\u003cli\u003eRestrict physical and logical access to the management and mesh-interconnect network segments to prevent adjacent network attackers from reaching the mesh protocol interfaces.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-25T05:12:20Z","date_published":"2026-08-25T05:12:20Z","id":"https://feed.craftedsignal.io/briefs/2026-08-tp-link-mesh-key/","summary":"A hard-coded RSA-512 private key in TP-Link Deco mesh firmware allows adjacent attackers to impersonate trusted nodes, enabling unauthorized configuration changes and firmware modification.","title":"Hard-coded RSA-512 Mesh Key in TP-Link Deco Routers","url":"https://feed.craftedsignal.io/briefs/2026-08-tp-link-mesh-key/"}],"language":"en","title":"CraftedSignal Threat Feed - Deco XE75","version":"https://jsonfeed.org/version/1.1"}