An authentication logic vulnerability in multiple TP-Link range extenders allows an unauthenticated attacker on an adjacent network to manipulate a login parameter and reset the administrator password due to insufficient validation.
Successful exploitation allows an attacker to obtain full administrative control of the affected device, potentially impacting on confidentiality, integrity, and availability.
References
Configurations
Configuration 1 (hide)
| AND |
|
Configuration 2 (hide)
| AND |
|
Configuration 3 (hide)
| AND |
|
Configuration 4 (hide)
| AND |
|
Configuration 5 (hide)
| AND |
|
History
No history.
Information
Published : 2026-05-22 21:16
Updated : 2026-07-23 11:10
NVD link : CVE-2026-3294
Mitre link : CVE-2026-3294
CVE.ORG link : CVE-2026-3294
JSON object : View
Products Affected
tp-link
- re580d_firmware
- re650_firmware
- tl-wa860re_firmware
- re650
- re580d
- re360_firmware
- tl-wa860re
- re305
- re305_firmware
- re360
