TP-Link Deco M5 Weak Password Hashing Vulnerability Allowing Credential Disclosure

Vulnerability

A vulnerability exists in the TP-Link Deco M5 v1 due to the use of a weak password hashing method for storing user credentials. This flaw allows an attacker who gains access to the password hash, either through system compromise or privileged access, to execute brute-force or dictionary attacks. Successful exploitation could lead to the unauthorized disclosure of authentication credentials, granting access to device management functions based on the privileges associated with the recovered password.

Impact

Exploitation of this vulnerability could result in unauthorized access to device management functions, depending on the privileges linked to the recovered password. This access could allow an attacker to manipulate device settings or functionalities.

Remediation

Users are advised to update their devices to the latest firmware version 1.9.4 Build 20260312, which addresses this vulnerability.

Added: Jul 15, 2026, 5:53 AM
Updated: Jul 15, 2026, 5:53 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
6.0
remediation
0.0
relevance
9.4
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.