Junglewise Threat Intelligence

CVE-2026-5040: TP-Link Deco M5 weak password hashing in firmware

CVE-2026-5040 · Severity: info · CVSS 7.1 · Published 2026-07-14

Vendors: TP-Link.

Executive brief

The TP-Link Deco M5, a popular mesh Wi-Fi router, uses an insecure method for protecting stored user passwords. If an attacker manages to gain high-level access to the device's internal system, they could easily crack these passwords using automated tools. This could lead to the full takeover of the device management functions and the exposure of sensitive administrative credentials.

Technical details

The TP-Link Deco M5 v1 (hardware version 1) utilizes a weak password hashing mechanism (CWE-916) for storing user credentials. The vulnerability requires an attacker to have already achieved a system compromise or possess high-privileged local access to obtain the password hashes. Once obtained, the lack of computational complexity in the hashing algorithm allows for successful offline brute-force or dictionary attacks. Successful exploitation results in the recovery of plaintext credentials, leading to unauthorized access to device management interfaces. This issue is addressed in firmware version 1.9.4 Build 20260312 Rel.17129 and later.

Affected products

  • TP-Link Systems Inc. Deco M5 Deco M5 V1 versions before 1.9.4 Build 20260312 Rel.17129

Timeline

  • 2026-03-12: patched: Firmware build date for the fix.
  • 2026-07-14: disclosed: Advisory published by TP-Link and NVD.

References