已识别出在 Deco XE75 v3、XE5300 v3.6 和 WE10800 v3.6 的 Mesh(网状网络)功能中存在硬编码加密密钥漏洞。受影响固件中包含一个共享的 RSA-512 Mesh 组私钥,Mesh 协议使用该密钥进行节点认证。攻击者若获取固件镜像并具备局域网访问权限,可能在未持有设备特定凭证的情况下,伪装成合法 Mesh 节点通过认证。 成功利用此漏洞可使未授权的邻近攻击者冒充受信任的 Mesh 节点,绕过 Mesh 节点身份验证机制,从而导致未经授权的设备或 Mesh 配置更改,进而影响系统的
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| TP-Link Systems Inc. | Deco XE75 v3 / XE5300 v3.6/ WE10800 v3.6 | < 1.5.0 Build 20260603 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| TP-Link Systems Inc. | Deco XE75 v3 / XE5300 v3.6/ WE10800 v3.6 | 0 ~ 1.5.0 Build 20260603 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-9254 | 8.7 HIGH | Command Injection Vulnerability in Parent Control of Multiple TP-Link Archer Devices |
| CVE-2026-16348 | 8.5 HIGH | Command Injection Vulnerability in VPN connection of Archer BE800 |
| CVE-2026-78541 | 8.5 HIGH | Command Injection in Parent Control of TP-Link Archer BE3600 v1 |
No comments yet