Executive brief
TP-Link Deco mesh Wi-Fi systems contain a hardcoded RSA-512 private key used to authenticate mesh nodes. An attacker with local network access who obtains the firmware can extract this key and impersonate trusted mesh devices, potentially gaining unauthorized control over network configuration and compromising data confidentiality, integrity, and availability.
Technical details
A shared RSA-512 mesh group private key is embedded in the firmware of affected Deco models and used by the mesh protocol for node authentication. The vulnerability is a hardcoded cryptographic key flaw in the mesh functionality. An adjacent attacker with local network access can obtain the firmware image and extract the key, then use it to authenticate as a mesh node without device-specific credentials, bypassing mesh node authentication. Successful exploitation permits unauthorized changes to device or mesh configuration. Patch availability is not specified in the advisory.
Affected products
- TP-Link Deco XE75 v3
- TP-Link Deco XE5300 v3.6
- TP-Link Deco WE10800 v3.6
Timeline
- 2026-08-24: disclosed