Weak password hashing in TP-Link Deco M5 can expose management credentials

Note: This data is for reference and cybersecurity research purposes only.CyStack advises users not to use this information for unlawful purposes.

What is CVE-2026-5040?

CVE-2026-5040 is a vulnerability classified as Use of Password Hash With Insufficient Computational Effort, affecting Deco M5 Deco M5 V1 (affected versions: < 1.9.4 Build 20260312 Rel.17129). This vulnerability is rated High, with a CVSS score of 7.1. Current sources do not report this vulnerability as exploited.

Overview

Original source data

TP-Link Deco M5 v1 uses a weak password hashing mechanism to store user credentials. An attacker who obtains the password hash through system compromise or privileged access could perform brute-force or dictionary attacks. Successful exploitation may result in disclosure of authentication credentials, enabling unauthorized access to device management functions, depending on the privileges associated with the recovered password. The primary security impact is loss of confidentiality.

Affected products and scope

  • TP-Link Deco M5, hardware version v1: firmware releases less than 1.9.4 Build 20260312 Rel.17129 are identified as affected.
  • TP-Link identifies 1.9.4 Build 20260312 Rel.17129 as the fixed firmware for Deco M5 v1.
  • The supplied evidence does not establish the exposure of other hardware revisions or parallel product branches. Do not infer the status of unlisted branches solely from this fixed release.

Technical details

TP-Link Deco M5 uses a password-hashing mechanism with insufficient computational effort to store user credentials. The weakness is classified as CWE-916 and affects the firmware's credential-storage mechanism. An attacker must first obtain the password hash through system compromise or privileged access, then can try candidate passwords using brute-force or dictionary attacks. The supplied attack characterization is local, requires high privileges, has high complexity, and does not require user interaction. The available evidence does not identify the hashing algorithm, hash location, salt, work factor, or extraction path.

Exploitability

The record does not describe direct network exploitation. An attacker needs local access with high privileges or must obtain the password hash through another system compromise. Once the hash is available, brute-force or dictionary guessing can be performed without user interaction, but the record provides no payload, tool, or detailed exploit sequence. The record does not mark the issue as known exploited and does not identify a public exploit; the actual exploitation status is therefore limited to the available evidence.

Technical impact

The weakness reduces the effort required to guess a password from an exposed password hash, which can disclose authentication credentials. If the recovered password belongs to an account with management privileges, an attacker may gain unauthorized access to device-management functions and may perform actions allowed by that account. The primary documented consequence is loss of confidentiality; integrity or availability effects depend on what the recovered credential is authorized to do. The record does not establish direct remote exploitation or impact on subsequent systems.

Business impact

  • User credentials may be disclosed if an attacker obtains the password hash and recovers the password.
  • A credential with greater privileges may enable unauthorized access to device-management functions, with the scope depending on the privileges assigned to the recovered account.
  • The primary risk is loss of confidentiality for authentication information; configuration changes or operational effects remain dependent on the permissions of the recovered credential.
  • If the credential is reused elsewhere, the exposed password may broaden the investigation scope, but the record does not establish compromise of other systems.

Remediation

  1. Update TP-Link Deco M5 hardware version v1 to the firmware TP-Link identifies as fixed: 1.9.4 Build 20260312 Rel.17129.
  2. Obtain firmware from the official TP-Link support page for the device's purchase region and verify the hardware version before upgrading. Do not install firmware intended for another revision.
  3. If there is evidence that a password hash or credential was accessed, rotate the device credential after updating and investigate accounts that reused the same password.
  4. Do not treat the presence of a newer firmware listing as proof that every branch or hardware revision has been verified; reconcile the model, revision, and TP-Link fix information for the specific device.

Detection

  • Inventory TP-Link Deco M5 devices and verify the hardware version before assessing firmware exposure.
  • Record the installed firmware and compare it with the fixed-version boundary documented by TP-Link.
  • Review privileged-access events and signs of system compromise that could have allowed a password hash to be read or obtained. This is a precautionary review, not a vendor-confirmed indicator of compromise.
  • If a hash or credential may have been accessed, investigate the access scope, rotate the related credential, and check for password reuse in other systems.
  • Do not treat the absence of log evidence or suspicious activity as proof that a device is safe.
Sources (14)
Learn more

Run an in-depth assessment with complete web risk management

CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.

Explore CyStack VulnScan