---
id: CVE-2026-3294
title: >-
  An authentication logic vulnerability in multiple TP-Link range extenders
  allows an unauthenticated attacker on an adjacent network to manipulate a
  login parameter and reset the administrator password due to insufficient
  validation.


  Suc…
summary: >-
  An authentication logic vulnerability in multiple TP-Link range extenders
  allows an unauthenticated attacker on an adjacent network to manipulate a
  login parameter and reset the administrator password due to insufficient
  validation.


  Suc…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-20
  - CWE-862
vendor: tp-link
product: re305_firmware
affected:
  - re305_firmware < 20260515
  - re360_firmware < 20260515
  - re580d_firmware < 20260515
  - re650_firmware < 20260429
  - tl-wa860re_firmware < 20260515
patched:
  - re305_firmware 20260515
  - re360_firmware 20260515
  - re580d_firmware 20260515
  - re650_firmware 20260429
  - tl-wa860re_firmware 20260515
published: '2026-05-22'
updated: '2026-07-23'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-3294'
references:
  - url: 'https://www.tp-link.com/en/support/download/re305/v1/#Firmware'
    label: f23511db-6c3e-4e32-a477-6aa17d310630
  - url: 'https://www.tp-link.com/en/support/download/re360/v1/#Firmware'
    label: f23511db-6c3e-4e32-a477-6aa17d310630
  - url: 'https://www.tp-link.com/en/support/download/re580d/#Firmware'
    label: f23511db-6c3e-4e32-a477-6aa17d310630
  - url: 'https://www.tp-link.com/en/support/download/re650/v1/#Firmware'
    label: f23511db-6c3e-4e32-a477-6aa17d310630
  - url: 'https://www.tp-link.com/en/support/download/tl-wa860re/v4/#Firmware'
    label: f23511db-6c3e-4e32-a477-6aa17d310630
  - url: 'https://www.tp-link.com/us/support/download/re305/v1/#Firmware'
    label: f23511db-6c3e-4e32-a477-6aa17d310630
  - url: 'https://www.tp-link.com/us/support/download/re360/v1/#Firmware'
    label: f23511db-6c3e-4e32-a477-6aa17d310630
  - url: 'https://www.tp-link.com/us/support/download/re580d/#Firmware'
    label: f23511db-6c3e-4e32-a477-6aa17d310630
  - url: 'https://www.tp-link.com/us/support/download/re650/v1/#Firmware'
    label: f23511db-6c3e-4e32-a477-6aa17d310630
  - url: 'https://www.tp-link.com/us/support/download/tl-wa860re/v4/#Firmware'
    label: f23511db-6c3e-4e32-a477-6aa17d310630
  - url: 'https://www.tp-link.com/us/support/faq/5101/'
    label: f23511db-6c3e-4e32-a477-6aa17d310630
tags:
  - nvd
epss: 0.00398
epssPercentile: 0.33809
ingestedAt: '2026-07-23T11:17:34.157Z'
---

## Overview

An authentication logic vulnerability in multiple TP-Link range extenders allows an unauthenticated attacker on an adjacent network to manipulate a login parameter and reset the administrator password due to insufficient validation.

Successful exploitation allows an attacker to obtain full administrative control of the affected device, potentially impacting on confidentiality, integrity, and availability.

## Affected

- `re305_firmware < 20260515`
- `re360_firmware < 20260515`
- `re580d_firmware < 20260515`
- `re650_firmware < 20260429`
- `tl-wa860re_firmware < 20260515`

## Remediation

Upgrade past the affected range:

- `re305_firmware 20260515`
- `re360_firmware 20260515`
- `re580d_firmware 20260515`
- `re650_firmware 20260429`
- `tl-wa860re_firmware 20260515`
