CVE-2026-3294

An authentication logic vulnerability in multiple TP-Link range extenders allows an unauthenticated attacker on an adjacent network to manipulate a login parameter and reset the administrator password due to insufficient validation. Successful exploitation allows an attacker to obtain full administrative control of the affected device, potentially impacting on confidentiality, integrity, and availability.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:tp-link:re305_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:re305:1.0:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:tp-link:re360_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:re360:1.0:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:tp-link:re580d_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:re580d:1.0:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:tp-link:re650_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:re650:1.0:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:tp-link:tl-wa860re_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:tl-wa860re:4.0:*:*:*:*:*:*:*

History

01 Jun 2026, 18:03

Type Values Removed Values Added
CWE CWE-862
References () https://www.tp-link.com/en/support/download/re305/v1/#Firmware - () https://www.tp-link.com/en/support/download/re305/v1/#Firmware - Product
References () https://www.tp-link.com/en/support/download/re360/v1/#Firmware - () https://www.tp-link.com/en/support/download/re360/v1/#Firmware - Product
References () https://www.tp-link.com/en/support/download/re580d/#Firmware - () https://www.tp-link.com/en/support/download/re580d/#Firmware - Product
References () https://www.tp-link.com/en/support/download/re650/v1/#Firmware - () https://www.tp-link.com/en/support/download/re650/v1/#Firmware - Product
References () https://www.tp-link.com/en/support/download/tl-wa860re/v4/#Firmware - () https://www.tp-link.com/en/support/download/tl-wa860re/v4/#Firmware - Product
References () https://www.tp-link.com/us/support/download/re305/v1/#Firmware - () https://www.tp-link.com/us/support/download/re305/v1/#Firmware - Product
References () https://www.tp-link.com/us/support/download/re360/v1/#Firmware - () https://www.tp-link.com/us/support/download/re360/v1/#Firmware - Product
References () https://www.tp-link.com/us/support/download/re580d/#Firmware - () https://www.tp-link.com/us/support/download/re580d/#Firmware - Product
References () https://www.tp-link.com/us/support/download/re650/v1/#Firmware - () https://www.tp-link.com/us/support/download/re650/v1/#Firmware - Product
References () https://www.tp-link.com/us/support/download/tl-wa860re/v4/#Firmware - () https://www.tp-link.com/us/support/download/tl-wa860re/v4/#Firmware - Product
References () https://www.tp-link.com/us/support/faq/5101/ - () https://www.tp-link.com/us/support/faq/5101/ - Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8
CPE cpe:2.3:h:tp-link:re305:1.0:*:*:*:*:*:*:*
cpe:2.3:o:tp-link:re650_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:tp-link:tl-wa860re_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:re360:1.0:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:tl-wa860re:4.0:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:re650:1.0:*:*:*:*:*:*:*
cpe:2.3:o:tp-link:re360_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:re580d:1.0:*:*:*:*:*:*:*
cpe:2.3:o:tp-link:re305_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:tp-link:re580d_firmware:*:*:*:*:*:*:*:*
First Time Tp-link
Tp-link re650 Firmware
Tp-link re360
Tp-link tl-wa860re
Tp-link re580d Firmware
Tp-link re305 Firmware
Tp-link re305
Tp-link re650
Tp-link re580d
Tp-link re360 Firmware
Tp-link tl-wa860re Firmware

22 May 2026, 21:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-22 21:16

Updated : 2026-06-01 18:03


NVD link : CVE-2026-3294

Mitre link : CVE-2026-3294

CVE.ORG link : CVE-2026-3294


JSON object : View

Products Affected

tp-link

  • tl-wa860re
  • re580d
  • re650
  • re305_firmware
  • re580d_firmware
  • re360_firmware
  • tl-wa860re_firmware
  • re305
  • re650_firmware
  • re360
CWE
CWE-20

Improper Input Validation

CWE-862

Missing Authorization