<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Deco XE75 - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/deco-xe75/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 25 Aug 2026 05:12:20 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/deco-xe75/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Hard-coded RSA-512 Mesh Key in TP-Link Deco Routers</title><link>https://feed.craftedsignal.io/briefs/2026-08-tp-link-mesh-key/</link><pubDate>Tue, 25 Aug 2026 05:12:20 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-tp-link-mesh-key/</guid><description>A hard-coded RSA-512 private key in TP-Link Deco mesh firmware allows adjacent attackers to impersonate trusted nodes, enabling unauthorized configuration changes and firmware modification.</description><content:encoded><![CDATA[<p>TP-Link Deco XE75, XE5300, and WE10800 mesh networking devices contain a hard-coded RSA-512 cryptographic key used for mesh group authentication (TDP/TMP protocols). Because this key is identical across all units of the affected models, an attacker with local network access to the mesh environment can extract the key from publicly available firmware images. Using this key, an attacker can impersonate a legitimate mesh node during the authentication handshake. This vulnerability, tracked as CVE-2026-15469, facilitates critical risks including unauthorized configuration changes, the deployment of unsigned malicious firmware, and seamless lateral movement across the mesh network. The flaw was publicly disclosed following vendor coordination and a patch release. It is fixed in firmware version 1.5.0 Build 20260603 and later.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows for the complete compromise of the mesh network environment. Attackers can gain control over configuration settings, inject malicious firmware updates to maintain persistence, and pivot through the network as a trusted mesh node. This affects all deployments of the listed TP-Link Deco models that have not been updated to the corrected firmware version.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Update all TP-Link Deco XE75, XE5300, and WE10800 units to firmware version 1.5.0 Build 20260603 or newer immediately.</li>
<li>Audit mesh network traffic for unauthorized node onboarding or unusual administrative activity originated from unexpected MAC addresses.</li>
<li>Restrict physical and logical access to the management and mesh-interconnect network segments to prevent adjacent network attackers from reaching the mesh protocol interfaces.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>