An authentication logic vulnerability in multiple TP-Link range extenders allows an unauthenticated attacker on an adjacent network to manipulate a login parameter and reset the administrator password due to insufficient validation.

Successful exploitation allows an attacker to obtain full administrative control of the affected device, potentially impacting on confidentiality, integrity, and availability.

Project Subscriptions

Vendors Products
Tp-link Subscribe
Archer Re305 V1 Subscribe
Archer Re360 V1 Subscribe
Archer Re650 V1 Subscribe
Re580d V1 Subscribe
Tl-wa860re V4 Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 26 May 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 25 May 2026 12:15:00 +0000

Type Values Removed Values Added
First Time appeared Tp-link
Tp-link archer Re305 V1
Tp-link archer Re360 V1
Tp-link archer Re650 V1
Tp-link re580d V1
Tp-link tl-wa860re V4
Vendors & Products Tp-link
Tp-link archer Re305 V1
Tp-link archer Re360 V1
Tp-link archer Re650 V1
Tp-link re580d V1
Tp-link tl-wa860re V4

Fri, 22 May 2026 21:00:00 +0000

Type Values Removed Values Added
Description An authentication logic vulnerability in multiple TP-Link range extenders allows an unauthenticated attacker on an adjacent network to manipulate a login parameter and reset the administrator password due to insufficient validation. Successful exploitation allows an attacker to obtain full administrative control of the affected device, potentially impacting on confidentiality, integrity, and availability.
Title Authentication Logic Vulnerability on Multiple TP-Link Range Extenders
Weaknesses CWE-20
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: TPLink

Published:

Updated: 2026-05-27T03:55:44.061Z

Reserved: 2026-02-26T19:00:32.766Z

Link: CVE-2026-3294

cve-icon Vulnrichment

Updated: 2026-05-26T14:44:43.043Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-05-22T21:16:42.960

Modified: 2026-05-26T19:08:15.080

Link: CVE-2026-3294

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-25T11:33:47Z

Weaknesses