Answer in brief
CVE-2026-15469 records a Unknown severity vulnerability in Hard-coded Mesh Group Private Key in TP-Link Deco XE75, XE5300, and WE10800. The current sources do not mark it as known exploited. The current feed maps TP-Link Systems Inc./Deco XE75 v3 / XE5300 v3.6/ WE10800 v3.6 (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps TP-Link Systems Inc./Deco XE75 v3 / XE5300 v3.6/ WE10800 v3.6 (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| TP-Link Systems Inc./Deco XE75 v3 / XE5300 v3.6/ WE10800 v3.6generic | >=0 <1.5.0 Build 20260603 | 1.5.0 Build 20260603 |
Published upstream
Aug 24, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 24, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 24, 2026
The use of hard-coded cryptographic key vulnerability has been identified in the mesh functionality of Deco XE75 v3, XE5300 v3.6 and WE10800 v3.6. A shared RSA-512 mesh group private key is present in the affected firmware and is used by the mesh protocol for node authentication. An attacker who obtains the firmware image and has local network access may be able to authenticate as a mesh node without possessing a device-specific credential. Successful exploitation may allow an unauthenticated adjacent attacker to impersonate a trusted mesh node and bypass mesh node authentication, which may permit unauthorized changes to device or mesh configuration, affecting confidentiality, integrity and availability.
Quoted source text, attributed separately from HOL analysis.