CVE-2026-3294
An authentication logic vulnerability in multiple TP-Link range extenders allows an unauthenticated attacker on an adjacent network to manipulate a login parameter and reset the administrator password due to insufficient validation.
Successful exploitation allows an attacker to obtain full administrative control of the affected device, potentially impacting on confidentiality, integrity, and availability.
CVSS
- Version: 4.0
- Vector: CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Base score: 8.7
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.57%
- Percentile among all scored CVEs: 45
- Score date: 10/5/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
🎯 ATT&CK techniques
How this vulnerability is exploited and what the attacker gains, in MITRE ATT&CK terms.
- Exploitation
T1210Exploitation of Remote Serviceslateral movement60 % - Primary impact
T1078Valid Accountsstealth · persistence · privilege escalation · initial access55 %
Inferred by deterministic rules from the CVSS vector and CWE. Indicative only.
🛡️ ATT&CK mitigations that cover these techniques
Affected technologies (5)
CWEs
- CWE-20
- CWE-862
References
- https://www.tp-link.com/en/support/download/re305/v1/#Firmware
- https://www.tp-link.com/en/support/download/re360/v1/#Firmware
- https://www.tp-link.com/en/support/download/re580d/#Firmware
- https://www.tp-link.com/en/support/download/re650/v1/#Firmware
- https://www.tp-link.com/en/support/download/tl-wa860re/v4/#Firmware
- https://www.tp-link.com/us/support/download/re305/v1/#Firmware
- https://www.tp-link.com/us/support/download/re360/v1/#Firmware
- https://www.tp-link.com/us/support/download/re580d/#Firmware
- https://www.tp-link.com/us/support/download/re650/v1/#Firmware
- https://www.tp-link.com/us/support/download/tl-wa860re/v4/#Firmware
- https://www.tp-link.com/us/support/faq/5101/
Raw JSON (NVD)
Show
{
"id": "CVE-2026-3294",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-3294",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2026-05-26T00:00:00+00:00"
}
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8.8,
"attackVector": "ADJACENT_NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 2.8
}
],
"cvssMetricV40": [
{
"type": "Secondary",
"source": "f23511db-6c3e-4e32-a477-6aa17d310630",
"cvssData": {
"Safety": "NOT_DEFINED",
"version": "4.0",
"Recovery": "NOT_DEFINED",
"baseScore": 8.7,
"Automatable": "NOT_DEFINED",
"attackVector": "ADJACENT",
"baseSeverity": "HIGH",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"exploitMaturity": "NOT_DEFINED",
"providerUrgency": "NOT_DEFINED",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"privilegesRequired": "NONE",
"subIntegrityImpact": "NONE",
"vulnIntegrityImpact": "HIGH",
"integrityRequirement": "NOT_DEFINED",
"modifiedAttackVector": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"vulnAvailabilityImpact": "HIGH",
"availabilityRequirement": "NOT_DEFINED",
"modifiedUserInteraction": "NOT_DEFINED",
"modifiedAttackComplexity": "NOT_DEFINED",
"subConfidentialityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"confidentialityRequirement": "NOT_DEFINED",
"modifiedAttackRequirements": "NOT_DEFINED",
"modifiedPrivilegesRequired": "NOT_DEFINED",
"modifiedSubIntegrityImpact": "NOT_DEFINED",
"modifiedVulnIntegrityImpact": "NOT_DEFINED",
"vulnerabilityResponseEffort": "NOT_DEFINED",
"modifiedSubAvailabilityImpact": "NOT_DEFINED",
"modifiedVulnAvailabilityImpact": "NOT_DEFINED",
"modifiedSubConfidentialityImpact": "NOT_DEFINED",
"modifiedVulnConfidentialityImpact": "NOT_DEFINED"
}
}
]
},
"affected": [
{
"source": "f23511db-6c3e-4e32-a477-6aa17d310630",
"affectedData": [
{
"vendor": "TP-Link Systems Inc.",
"product": "Archer RE650 v1",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "V1_20260429",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "TP-Link Systems Inc.",
"product": "Archer RE305 v1",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "V1_20260515",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "TP Link Systems Inc.",
"product": "Archer RE360 v1",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "V1_20260515",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "TP-Link Systems Inc.",
"product": "TL-WA860RE v4",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "V4_20260515",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "TP-Link Systems Inc.",
"product": "RE580D v1",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "V1_20260515",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2026-05-22T21:16:42.960",
"references": [
{
"url": "https://www.tp-link.com/en/support/download/re305/v1/#Firmware",
"tags": [
"Product"
],
"source": "f23511db-6c3e-4e32-a477-6aa17d310630"
},
{
"url": "https://www.tp-link.com/en/support/download/re360/v1/#Firmware",
"tags": [
"Product"
],
"source": "f23511db-6c3e-4e32-a477-6aa17d310630"
},
{
"url": "https://www.tp-link.com/en/support/download/re580d/#Firmware",
"tags": [
"Product"
],
"source": "f23511db-6c3e-4e32-a477-6aa17d310630"
},
{
"url": "https://www.tp-link.com/en/support/download/re650/v1/#Firmware",
"tags": [
"Product"
],
"source": "f23511db-6c3e-4e32-a477-6aa17d310630"
},
{
"url": "https://www.tp-link.com/en/support/download/tl-wa860re/v4/#Firmware",
"tags": [
"Product"
],
"source": "f23511db-6c3e-4e32-a477-6aa17d310630"
},
{
"url": "https://www.tp-link.com/us/support/download/re305/v1/#Firmware",
"tags": [
"Product"
],
"source": "f23511db-6c3e-4e32-a477-6aa17d310630"
},
{
"url": "https://www.tp-link.com/us/support/download/re360/v1/#Firmware",
"tags": [
"Product"
],
"source": "f23511db-6c3e-4e32-a477-6aa17d310630"
},
{
"url": "https://www.tp-link.com/us/support/download/re580d/#Firmware",
"tags": [
"Product"
],
"source": "f23511db-6c3e-4e32-a477-6aa17d310630"
},
{
"url": "https://www.tp-link.com/us/support/download/re650/v1/#Firmware",
"tags": [
"Product"
],
"source": "f23511db-6c3e-4e32-a477-6aa17d310630"
},
{
"url": "https://www.tp-link.com/us/support/download/tl-wa860re/v4/#Firmware",
"tags": [
"Product"
],
"source": "f23511db-6c3e-4e32-a477-6aa17d310630"
},
{
"url": "https://www.tp-link.com/us/support/faq/5101/",
"tags": [
"Vendor Advisory"
],
"source": "f23511db-6c3e-4e32-a477-6aa17d310630"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "f23511db-6c3e-4e32-a477-6aa17d310630",
"description": [
{
"lang": "en",
"value": "CWE-20"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-862"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "An authentication logic vulnerability in multiple TP-Link range extenders allows an unauthenticated attacker on an adjacent network to manipulate a login parameter and reset the administrator password due to insufficient validation.\n\nSuccessful exploitation allows an attacker to obtain full administrative control of the affected device, potentially impacting on confidentiality, integrity, and availability."
},
{
"lang": "es",
"value": "Una vulnerabilidad de lógica de autenticación en múltiples extensores de rango TP-Link permite a un atacante no autenticado en una red adyacente manipular un parámetro de inicio de sesión y restablecer la contraseña del administrador debido a validación insuficiente.\n\nLa explotación exitosa permite a un atacante obtener control administrativo total del dispositivo afectado, impactando potencialmente en la confidencialidad, la integridad y la disponibilidad."
}
],
"lastModified": "2026-07-23T11:10:00.120",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:tp-link:re305_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A76ABE71-C8ED-431F-A699-C87B502DE6FF",
"versionEndExcluding": "20260515"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:tp-link:re305:1.0:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "EB800EB4-8027-4071-85B1-A3D5D4426CF7"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:tp-link:re360_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "06997C4E-9063-443E-84AC-458940CE880E",
"versionEndExcluding": "20260515"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:tp-link:re360:1.0:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "5D16136E-606D-4E4F-9310-59B0C24275D0"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:tp-link:re580d_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EBC0C4A7-632D-4979-94F7-0C17C40B7576",
"versionEndExcluding": "20260515"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:tp-link:re580d:1.0:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "9F8FB56B-F9DC-491A-ADC3-8170CDF0052F"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:tp-link:re650_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "023F0049-F1F0-4700-967C-5B27DB497229",
"versionEndExcluding": "20260429"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:tp-link:re650:1.0:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "68ED1297-85DE-4C5C-8095-E67542D11057"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:tp-link:tl-wa860re_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AEAF244D-4960-4016-B227-7B1A3F1A63EF",
"versionEndExcluding": "20260515"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:tp-link:tl-wa860re:4.0:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "A6C69006-B712-45E4-AE72-BA947300DD5D"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "f23511db-6c3e-4e32-a477-6aa17d310630"
}