SEPTEMBER 12, 2026
Live Feed
Back to database
Case File

CVE-2026-5040

MEDIUM · CVSS 6.7 EPSS 0.09% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-14 · Last synced 2026-08-13

CyberRota Analysis

AI-Generated

The TP-Link Deco M5 v1 is vulnerable due to its use of a weak password hashing mechanism for storing user credentials. This weakness allows attackers with system access to potentially recover passwords through brute-force or dictionary attacks, leading to unauthorized access to device management functions and a significant loss of confidentiality. Organizations using this device should prioritize addressing this vulnerability to safeguard their network security.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-5040
Severity
MEDIUM
CVSS
6.7
EPSS
0.09%

Original NVD Description

TP-Link Deco M5 v1 uses a weak password hashing mechanism to store user credentials. An attacker who obtains the password hash through system compromise or privileged access could perform brute-force or dictionary attacks. Successful exploitation may result in disclosure of authentication credentials, enabling unauthorized access to device management functions, depending on the privileges associated with the recovered password. The primary security impact is loss of confidentiality.

Related CVEs

Other vulnerabilities affecting the same vendor(s)