MEDIUMVulnerability

CVE-2026-5040

TP-Link Deco M5 v1 uses a weak password hashing mechanism to store user credentials. An attacker who obtains the password hash through system compromise or privileged access could perform brute-force or dictionary attacks. Successful exploitation may result in disclosure of authentication credentials, enabling unauthorized access to device management functions, depending on the privileges associated with the recovered password. The primary security impact is loss of confidentiality.

Properties

severity
MEDIUM
score
6.7
cve_id
CVE-2026-5040
vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
published_at
2026-07-14T19:18:03.213
last_modified
2026-08-06T18:26:03.690

Related Entities (4)

HAS_WEAKNESS (1)

[Weakness]Use of Password Hash With Insufficient Computational Effort

DESCRIBED_BY (1)

[Source]NVD

AFFECTS_PRODUCT (2)

[Product]
[Product]

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-5040 — Ninja Signal Threat Intelligence | Ninja Signal