{"id":"CVE-2026-3294","title":"An authentication logic vulnerability in multiple TP-Link range extenders allows an unauthenticated attacker on an adjacent network to manipulate a login parameter and reset the administrator password due to insufficient validation.\n\nSuc…","summary":"An authentication logic vulnerability in multiple TP-Link range extenders allows an unauthenticated attacker on an adjacent network to manipulate a login parameter and reset the administrator password due to insufficient validation.\n\nSuc…","severity":"high","cvss":8.8,"cvssVector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-20","CWE-862"],"vendor":"tp-link","product":"re305_firmware","affected":["re305_firmware < 20260515","re360_firmware < 20260515","re580d_firmware < 20260515","re650_firmware < 20260429","tl-wa860re_firmware < 20260515"],"patched":["re305_firmware 20260515","re360_firmware 20260515","re580d_firmware 20260515","re650_firmware 20260429","tl-wa860re_firmware 20260515"],"published":"2026-05-22","updated":"2026-07-23","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-3294","references":[{"url":"https://www.tp-link.com/en/support/download/re305/v1/#Firmware","label":"f23511db-6c3e-4e32-a477-6aa17d310630"},{"url":"https://www.tp-link.com/en/support/download/re360/v1/#Firmware","label":"f23511db-6c3e-4e32-a477-6aa17d310630"},{"url":"https://www.tp-link.com/en/support/download/re580d/#Firmware","label":"f23511db-6c3e-4e32-a477-6aa17d310630"},{"url":"https://www.tp-link.com/en/support/download/re650/v1/#Firmware","label":"f23511db-6c3e-4e32-a477-6aa17d310630"},{"url":"https://www.tp-link.com/en/support/download/tl-wa860re/v4/#Firmware","label":"f23511db-6c3e-4e32-a477-6aa17d310630"},{"url":"https://www.tp-link.com/us/support/download/re305/v1/#Firmware","label":"f23511db-6c3e-4e32-a477-6aa17d310630"},{"url":"https://www.tp-link.com/us/support/download/re360/v1/#Firmware","label":"f23511db-6c3e-4e32-a477-6aa17d310630"},{"url":"https://www.tp-link.com/us/support/download/re580d/#Firmware","label":"f23511db-6c3e-4e32-a477-6aa17d310630"},{"url":"https://www.tp-link.com/us/support/download/re650/v1/#Firmware","label":"f23511db-6c3e-4e32-a477-6aa17d310630"},{"url":"https://www.tp-link.com/us/support/download/tl-wa860re/v4/#Firmware","label":"f23511db-6c3e-4e32-a477-6aa17d310630"},{"url":"https://www.tp-link.com/us/support/faq/5101/","label":"f23511db-6c3e-4e32-a477-6aa17d310630"}],"tags":["nvd"],"epss":0.00398,"epssPercentile":0.33724,"ingestedAt":"2026-07-23T11:17:34.157Z","slug":"CVE-2026-3294","body":"## Overview\n\nAn authentication logic vulnerability in multiple TP-Link range extenders allows an unauthenticated attacker on an adjacent network to manipulate a login parameter and reset the administrator password due to insufficient validation.\n\nSuccessful exploitation allows an attacker to obtain full administrative control of the affected device, potentially impacting on confidentiality, integrity, and availability.\n\n## Affected\n\n- `re305_firmware < 20260515`\n- `re360_firmware < 20260515`\n- `re580d_firmware < 20260515`\n- `re650_firmware < 20260429`\n- `tl-wa860re_firmware < 20260515`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `re305_firmware 20260515`\n- `re360_firmware 20260515`\n- `re580d_firmware 20260515`\n- `re650_firmware 20260429`\n- `tl-wa860re_firmware 20260515`","depth":"twilight","depthScore":48,"depthScoreParts":{"impact":48.4,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}