CVE-2026-5040

TP-Link Deco M5 v1 uses a weak password hashing mechanism to store user credentials. An attacker who obtains the password hash through system compromise or privileged access could perform brute-force or dictionary attacks. Successful exploitation may result in disclosure of authentication credentials, enabling unauthorized access to device management functions, depending on the privileges associated with the recovered password. The primary security impact is loss of confidentiality.
CVSS

No CVSS.

Configurations

No configuration.

History

14 Jul 2026, 19:18

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-14 19:18

Updated : 2026-07-15 20:08


NVD link : CVE-2026-5040

Mitre link : CVE-2026-5040

CVE.ORG link : CVE-2026-5040


JSON object : View

Products Affected

No product.

CWE
CWE-916

Use of Password Hash With Insufficient Computational Effort