CVE-2026-3294 Details
Description
An authentication logic vulnerability in multiple TP-Link range extenders allows an unauthenticated attacker on an adjacent network to manipulate a login parameter and reset the administrator password due to insufficient validation. Successful exploitation allows an attacker to obtain full administrative control of the affected device, potentially impacting on confidentiality, integrity, and availability.
A vulnerability in the authentication logic of several TP-Link range extenders enables an unauthenticated attacker on an adjacent network to manipulate a login parameter and reset the administrator password, exploiting inadequate validation. This exploitation grants full administrative control over the affected device, with potential repercussions for confidentiality, integrity, and availability.
Users are advised to update to the latest firmware version available on the TP-Link official website. Specific download links for the updated firmware are provided in the TP-Link security advisory.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 26, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.tp-link.com/en/support/download/re305/v1/#Firmware | TPLink | Product |
| https://www.tp-link.com/en/support/download/re360/v1/#Firmware | TPLink | Product |
| https://www.tp-link.com/en/support/download/re580d/#Firmware | TPLink | Product |
| https://www.tp-link.com/en/support/download/re650/v1/#Firmware | TPLink | Product |
| https://www.tp-link.com/en/support/download/tl-wa860re/v4/#Firmware | TPLink | Product |
| https://www.tp-link.com/us/support/download/re305/v1/#Firmware | TPLink | Product |
| https://www.tp-link.com/us/support/download/re360/v1/#Firmware | TPLink | Product |
| https://www.tp-link.com/us/support/download/re580d/#Firmware | TPLink | Product |
| https://www.tp-link.com/us/support/download/re650/v1/#Firmware | TPLink | Product |
| https://www.tp-link.com/us/support/download/tl-wa860re/v4/#Firmware | TPLink | Product |
| https://www.tp-link.com/us/support/faq/5101/ | TPLink | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-862 | Missing Authorization | [email protected] |
| CWE-20 | Improper Input Validation | TPLink |
Affected Products
| Product | Versions |
|---|---|
| tp-link re305 firmware | < 20260515 |
CPE
Remediation
| |
| tp-link re305 | 1.0 |
CPE
Remediation
| |
| tp-link re360 firmware | < 20260515 |
CPE
Remediation
| |
| tp-link re360 | 1.0 |
CPE
Remediation
| |
| tp-link re580d firmware | < 20260515 |
CPE
Remediation
| |
| tp-link re580d | 1.0 |
CPE
Remediation
| |
| tp-link re650 firmware | < 20260429 |
CPE
Remediation
| |
| tp-link re650 | 1.0 |
CPE
Remediation
| |
| tp-link tl-wa860re firmware | < 20260515 |
CPE
Remediation
| |
| tp-link tl-wa860re | 4.0 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 23, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | TPLink |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 1, 2026 | Initial Analysis | [email protected] |
| May 22, 2026 | New CVE Received | TPLink |