CVE-2026-3294
An authentication logic vulnerability in multiple TP-Link range extenders allows an unauthenticated attacker on an adjacent network to manipulate a login parameter and reset the administrator password due to insufficient validation.
Successful exploitation allows an attacker to obtain full administrative control of the affected device, potentially impacting on confidentiality, integrity, and availability.
CVSS
- Versión: 4.0
- Vector: CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Puntuación base: 8.7
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.57%
- Percentil entre todas las CVEs puntuadas: 45
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1210Exploitation of Remote Serviceslateral movement60 % - Impacto principal
T1078Valid Accountsstealth · persistence · privilege escalation · initial access55 %
Inferido por reglas deterministas a partir del vector CVSS y la CWE. Solo orientativo.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (5)
CWE
- CWE-20
- CWE-862
Referencias
- https://www.tp-link.com/en/support/download/re305/v1/#Firmware
- https://www.tp-link.com/en/support/download/re360/v1/#Firmware
- https://www.tp-link.com/en/support/download/re580d/#Firmware
- https://www.tp-link.com/en/support/download/re650/v1/#Firmware
- https://www.tp-link.com/en/support/download/tl-wa860re/v4/#Firmware
- https://www.tp-link.com/us/support/download/re305/v1/#Firmware
- https://www.tp-link.com/us/support/download/re360/v1/#Firmware
- https://www.tp-link.com/us/support/download/re580d/#Firmware
- https://www.tp-link.com/us/support/download/re650/v1/#Firmware
- https://www.tp-link.com/us/support/download/tl-wa860re/v4/#Firmware
- https://www.tp-link.com/us/support/faq/5101/
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-3294",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-3294",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2026-05-26T00:00:00+00:00"
}
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8.8,
"attackVector": "ADJACENT_NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 2.8
}
],
"cvssMetricV40": [
{
"type": "Secondary",
"source": "f23511db-6c3e-4e32-a477-6aa17d310630",
"cvssData": {
"Safety": "NOT_DEFINED",
"version": "4.0",
"Recovery": "NOT_DEFINED",
"baseScore": 8.7,
"Automatable": "NOT_DEFINED",
"attackVector": "ADJACENT",
"baseSeverity": "HIGH",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"exploitMaturity": "NOT_DEFINED",
"providerUrgency": "NOT_DEFINED",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"privilegesRequired": "NONE",
"subIntegrityImpact": "NONE",
"vulnIntegrityImpact": "HIGH",
"integrityRequirement": "NOT_DEFINED",
"modifiedAttackVector": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"vulnAvailabilityImpact": "HIGH",
"availabilityRequirement": "NOT_DEFINED",
"modifiedUserInteraction": "NOT_DEFINED",
"modifiedAttackComplexity": "NOT_DEFINED",
"subConfidentialityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"confidentialityRequirement": "NOT_DEFINED",
"modifiedAttackRequirements": "NOT_DEFINED",
"modifiedPrivilegesRequired": "NOT_DEFINED",
"modifiedSubIntegrityImpact": "NOT_DEFINED",
"modifiedVulnIntegrityImpact": "NOT_DEFINED",
"vulnerabilityResponseEffort": "NOT_DEFINED",
"modifiedSubAvailabilityImpact": "NOT_DEFINED",
"modifiedVulnAvailabilityImpact": "NOT_DEFINED",
"modifiedSubConfidentialityImpact": "NOT_DEFINED",
"modifiedVulnConfidentialityImpact": "NOT_DEFINED"
}
}
]
},
"affected": [
{
"source": "f23511db-6c3e-4e32-a477-6aa17d310630",
"affectedData": [
{
"vendor": "TP-Link Systems Inc.",
"product": "Archer RE650 v1",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "V1_20260429",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "TP-Link Systems Inc.",
"product": "Archer RE305 v1",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "V1_20260515",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "TP Link Systems Inc.",
"product": "Archer RE360 v1",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "V1_20260515",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "TP-Link Systems Inc.",
"product": "TL-WA860RE v4",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "V4_20260515",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "TP-Link Systems Inc.",
"product": "RE580D v1",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "V1_20260515",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2026-05-22T21:16:42.960",
"references": [
{
"url": "https://www.tp-link.com/en/support/download/re305/v1/#Firmware",
"tags": [
"Product"
],
"source": "f23511db-6c3e-4e32-a477-6aa17d310630"
},
{
"url": "https://www.tp-link.com/en/support/download/re360/v1/#Firmware",
"tags": [
"Product"
],
"source": "f23511db-6c3e-4e32-a477-6aa17d310630"
},
{
"url": "https://www.tp-link.com/en/support/download/re580d/#Firmware",
"tags": [
"Product"
],
"source": "f23511db-6c3e-4e32-a477-6aa17d310630"
},
{
"url": "https://www.tp-link.com/en/support/download/re650/v1/#Firmware",
"tags": [
"Product"
],
"source": "f23511db-6c3e-4e32-a477-6aa17d310630"
},
{
"url": "https://www.tp-link.com/en/support/download/tl-wa860re/v4/#Firmware",
"tags": [
"Product"
],
"source": "f23511db-6c3e-4e32-a477-6aa17d310630"
},
{
"url": "https://www.tp-link.com/us/support/download/re305/v1/#Firmware",
"tags": [
"Product"
],
"source": "f23511db-6c3e-4e32-a477-6aa17d310630"
},
{
"url": "https://www.tp-link.com/us/support/download/re360/v1/#Firmware",
"tags": [
"Product"
],
"source": "f23511db-6c3e-4e32-a477-6aa17d310630"
},
{
"url": "https://www.tp-link.com/us/support/download/re580d/#Firmware",
"tags": [
"Product"
],
"source": "f23511db-6c3e-4e32-a477-6aa17d310630"
},
{
"url": "https://www.tp-link.com/us/support/download/re650/v1/#Firmware",
"tags": [
"Product"
],
"source": "f23511db-6c3e-4e32-a477-6aa17d310630"
},
{
"url": "https://www.tp-link.com/us/support/download/tl-wa860re/v4/#Firmware",
"tags": [
"Product"
],
"source": "f23511db-6c3e-4e32-a477-6aa17d310630"
},
{
"url": "https://www.tp-link.com/us/support/faq/5101/",
"tags": [
"Vendor Advisory"
],
"source": "f23511db-6c3e-4e32-a477-6aa17d310630"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "f23511db-6c3e-4e32-a477-6aa17d310630",
"description": [
{
"lang": "en",
"value": "CWE-20"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-862"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "An authentication logic vulnerability in multiple TP-Link range extenders allows an unauthenticated attacker on an adjacent network to manipulate a login parameter and reset the administrator password due to insufficient validation.\n\nSuccessful exploitation allows an attacker to obtain full administrative control of the affected device, potentially impacting on confidentiality, integrity, and availability."
},
{
"lang": "es",
"value": "Una vulnerabilidad de lógica de autenticación en múltiples extensores de rango TP-Link permite a un atacante no autenticado en una red adyacente manipular un parámetro de inicio de sesión y restablecer la contraseña del administrador debido a validación insuficiente.\n\nLa explotación exitosa permite a un atacante obtener control administrativo total del dispositivo afectado, impactando potencialmente en la confidencialidad, la integridad y la disponibilidad."
}
],
"lastModified": "2026-07-23T11:10:00.120",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:tp-link:re305_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A76ABE71-C8ED-431F-A699-C87B502DE6FF",
"versionEndExcluding": "20260515"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:tp-link:re305:1.0:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "EB800EB4-8027-4071-85B1-A3D5D4426CF7"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:tp-link:re360_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "06997C4E-9063-443E-84AC-458940CE880E",
"versionEndExcluding": "20260515"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:tp-link:re360:1.0:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "5D16136E-606D-4E4F-9310-59B0C24275D0"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:tp-link:re580d_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EBC0C4A7-632D-4979-94F7-0C17C40B7576",
"versionEndExcluding": "20260515"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:tp-link:re580d:1.0:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "9F8FB56B-F9DC-491A-ADC3-8170CDF0052F"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:tp-link:re650_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "023F0049-F1F0-4700-967C-5B27DB497229",
"versionEndExcluding": "20260429"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:tp-link:re650:1.0:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "68ED1297-85DE-4C5C-8095-E67542D11057"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:tp-link:tl-wa860re_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AEAF244D-4960-4016-B227-7B1A3F1A63EF",
"versionEndExcluding": "20260515"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:tp-link:tl-wa860re:4.0:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "A6C69006-B712-45E4-AE72-BA947300DD5D"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "f23511db-6c3e-4e32-a477-6aa17d310630"
}