CVE-2026-5040 Details
Description
TP-Link Deco M5 v1 uses a weak password hashing mechanism to store user credentials. An attacker who obtains the password hash through system compromise or privileged access could perform brute-force or dictionary attacks. Successful exploitation may result in disclosure of authentication credentials, enabling unauthorized access to device management functions, depending on the privileges associated with the recovered password. The primary security impact is loss of confidentiality.
A vulnerability exists in the TP-Link Deco M5 v1 due to the use of a weak password hashing method for storing user credentials. This flaw allows an attacker who gains access to the password hash, either through system compromise or privileged access, to execute brute-force or dictionary attacks. Successful exploitation could lead to the unauthorized disclosure of authentication credentials, granting access to device management functions based on the privileges associated with the recovered password.
Users are advised to update their devices to the latest firmware version 1.9.4 Build 20260312, which addresses this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 15, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.tp-link.com/en/support/download/deco-m5/v1/#Firmware | TPLink | Product |
| https://www.tp-link.com/us/support/download/deco-m5/v1/#Firmware | TPLink | Product |
| https://www.tp-link.com/us/support/faq/5190/ | TPLink | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-916 | Use of Password Hash With Insufficient Computational Effort | TPLink |
Affected Products
| Product | Versions |
|---|---|
| tp-link deco m5 firmware | < 1.9.4 |
CPE
Remediation
| |
| tp-link deco m5 | 1.0 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 6, 2026 | Initial Analysis | [email protected] |
| Jul 15, 2026 | CVE Modified | CISA-ADP |
| Jul 15, 2026 | CVE Modified | CISA-ADP |
| Jul 14, 2026 | New CVE Received | TPLink |