An authentication logic vulnerability in multiple TP-Link range extenders allows an unauthenticated attacker on an adjacent network to manipulate a login parameter and reset the administrator password due to insufficient validation. Successful exploitation allows an attacker to obtain full administrative control of the affected device, potentially impacting on confidentiality, integrity, and availability.
History

Mon, 25 May 2026 12:15:00 +0000

Type Values Removed Values Added
First Time appeared Tp-link
Tp-link archer Re305 V1
Tp-link archer Re360 V1
Tp-link archer Re650 V1
Tp-link re580d V1
Tp-link tl-wa860re V4
Vendors & Products Tp-link
Tp-link archer Re305 V1
Tp-link archer Re360 V1
Tp-link archer Re650 V1
Tp-link re580d V1
Tp-link tl-wa860re V4

Fri, 22 May 2026 21:00:00 +0000

Type Values Removed Values Added
Description An authentication logic vulnerability in multiple TP-Link range extenders allows an unauthenticated attacker on an adjacent network to manipulate a login parameter and reset the administrator password due to insufficient validation. Successful exploitation allows an attacker to obtain full administrative control of the affected device, potentially impacting on confidentiality, integrity, and availability.
Title Authentication Logic Vulnerability on Multiple TP-Link Range Extenders
Weaknesses CWE-20
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: TPLink

Published:

Updated: 2026-05-22T20:48:36.242Z

Reserved: 2026-02-26T19:00:32.766Z

Link: CVE-2026-3294

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-25T11:33:47Z