CVE Explorer
CVE-2026-5040
TP-Link Deco M5 v1 uses a weak password hashing mechanism to store user credentials. An attacker who obtains the password hash through system compromise or privileged access could perform brute-force or dictionary attacks.
Successful exploitation may result in disclosure of authentication credentials, enabling unauthorized access to device management functions, depending on the privileges associated with the recovered password. The primary security impact is loss of confidentiality.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","product":"Deco M5 Deco M5 V1","vendor":"TP-Link Systems Inc.","versions":[{"lessThan":"1.9.4 Build 20260312 Rel.17129","status":"affected","version":"0","versionType":"custom"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:f1994cd7de926532fce4253082978d55e1125dcb5a10ca9727a91433fffae955 · sha256:edbe5a12b4ed3300… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"HIGH","attackRequirements":"NONE","attackVector":"LOCAL","baseScore":7.1,"baseSeverity":"HIGH","exploitMaturity":"NOT_DEFINED","privilegesRequired":"HIGH","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnConfidentialityImpact":"H…
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:f1994cd7de926532fce4253082978d55e1125dcb5a10ca9727a91433fffae955 · sha256:edbe5a12b4ed3300… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-916","description":"CWE-916 Use of Password Hash With Insufficient Computational Effort","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:f1994cd7de926532fce4253082978d55e1125dcb5a10ca9727a91433fffae955 · sha256:edbe5a12b4ed3300… · /containers/cna/problemTypes/0/descriptions/0
Source references
3 source assertions{"url":"https://www.tp-link.com/en/support/download/deco-m5/v1/#Firmware"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:f1994cd7de926532fce4253082978d55e1125dcb5a10ca9727a91433fffae955 · sha256:edbe5a12b4ed3300… · /containers/cna/references/1
{"url":"https://www.tp-link.com/us/support/download/deco-m5/v1/#Firmware"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:f1994cd7de926532fce4253082978d55e1125dcb5a10ca9727a91433fffae955 · sha256:edbe5a12b4ed3300… · /containers/cna/references/0
{"url":"https://www.tp-link.com/us/support/faq/5190/"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:f1994cd7de926532fce4253082978d55e1125dcb5a10ca9727a91433fffae955 · sha256:edbe5a12b4ed3300… · /containers/cna/references/2
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.