CVE Database
/

CVE-2026-3294

Back to search

CVE-2026-3294

Published: May 22, 2026

Modified: May 27, 2026

PUBLISHED

Description

An authentication logic vulnerability in multiple TP-Link range extenders allows an unauthenticated attacker on an adjacent network to manipulate a login parameter and reset the administrator password due to insufficient validation. Successful exploitation allows an attacker to obtain full administrative control of the affected device, potentially impacting on confidentiality, integrity, and availability.

VendorProductVersions

TP-Link Systems Inc.

Archer RE650 v1

affected
0 - < V1_20260429

TP-Link Systems Inc.

Archer RE305 v1

affected
0 - < V1_20260515

TP Link Systems Inc.

Archer RE360 v1

affected
0 - < V1_20260515

TP-Link Systems Inc.

TL-WA860RE v4

affected
0 - < V4_20260515

TP-Link Systems Inc.

RE580D v1

affected
0 - < V1_20260515

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now