CVE-2026-5040: Weak Password Hashing Mechanism in TP-Link Deco M5
TP-Link Deco M5 v1 uses a weak password hashing mechanism to store user credentials. An attacker who obtains the password hash through system compromise or privileged access could perform brute-force or dictionary attacks.
Successful exploitation may result in disclosure of authentication credentials, enabling unauthorized access to device management functions, depending on the privileges associated with the recovered password. The primary security impact is loss of confidentiality.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-5040?
The severity of CVE-2026-5040 is high with a CVSS score of 7.1.
How do I fix CVE-2026-5040?
To fix CVE-2026-5040, update the TP-Link Deco M5 to the latest firmware version that addresses the weak password hashing mechanism.
What are the potential risks associated with CVE-2026-5040?
CVE-2026-5040 could allow attackers to perform brute-force or dictionary attacks on user credentials, leading to potential unauthorized access.
Which devices are affected by CVE-2026-5040?
CVE-2026-5040 specifically affects TP-Link Deco M5 v1 devices due to their weak password hashing mechanism.
How can I determine if my TP-Link Deco M5 is vulnerable to CVE-2026-5040?
You can determine if your TP-Link Deco M5 is vulnerable to CVE-2026-5040 by checking if it is running an outdated firmware that utilizes the weak password hashing mechanism.