Junglewise Threat Intelligence

CVE-2026-3294: TP-Link Range Extenders authentication bypass and password reset

CVE-2026-3294 · Severity: info · CVSS 8.7 · Published 2026-05-22

Vendors: TP-Link.

Executive brief

A security flaw in several TP-Link Wi-Fi range extenders allows an unauthorized person on the same local network to reset the administrator password. By manipulating specific login settings, an attacker can take full control of the device. This could allow them to monitor network traffic, change security settings, or disable the internet connection entirely.

Technical details

An authentication logic vulnerability exists in the web management interface of multiple TP-Link range extenders (RE305, RE360, RE580D, RE650, and TL-WA860RE). The flaw stems from improper input validation (CWE-20) of login parameters, which allows an unauthenticated attacker on an adjacent network (e.g., the same Wi-Fi or local LAN) to bypass authentication checks and reset the administrator password. Successful exploitation grants the attacker full administrative access to the device's configuration. TP-Link has released firmware updates for affected models to address this vulnerability.

Affected products

  • TP-Link RE305 V1
  • TP-Link RE360 V1
  • TP-Link RE580D V1
  • TP-Link RE650 V1
  • TP-Link TL-WA860RE V4

Timeline

  • 2026-05-15: patched: Firmware updates released for affected models (e.g., RE305 V1, RE360 V1)
  • 2026-05-22: disclosed: CVE published by TP-Link

References