CVE-2026-3294
An authentication logic vulnerability in multiple TP-Link range extenders allows an unauthenticated attacker on an adjacent network to manipulate a login parameter and reset the administrator password due to insufficient validation.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.40%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
An authentication logic vulnerability in multiple TP-Link range extenders allows an unauthenticated attacker on an adjacent network to manipulate a login parameter and reset the administrator password due to insufficient validation. Successful exploitation allows an attacker to obtain full administrative control of the affected device, potentially impacting on confidentiality, integrity, and availability.
- CVSS 4.0
- 8.7 HIGHCVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.40% probability · 33th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20, CWE-862
- Affected
- tp-link/re305 firmware · tp-link/re360 firmware · tp-link/re580d firmware · tp-link/re650 firmware · tp-link/tl-wa860re firmware
- Source
- f23511db-6c3e-4e32-a477-6aa17d310630
References
- https://www.tp-link.com/en/support/download/re305/v1/#FirmwareProduct
- https://www.tp-link.com/en/support/download/re360/v1/#FirmwareProduct
- https://www.tp-link.com/en/support/download/re580d/#FirmwareProduct
- https://www.tp-link.com/en/support/download/re650/v1/#FirmwareProduct
- https://www.tp-link.com/en/support/download/tl-wa860re/v4/#FirmwareProduct
- https://www.tp-link.com/us/support/download/re305/v1/#FirmwareProduct
- https://www.tp-link.com/us/support/download/re360/v1/#FirmwareProduct
- https://www.tp-link.com/us/support/download/re580d/#FirmwareProduct
- https://www.tp-link.com/us/support/download/re650/v1/#FirmwareProduct
- https://www.tp-link.com/us/support/download/tl-wa860re/v4/#FirmwareProduct
- https://www.tp-link.com/us/support/faq/5101/Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.