CVE-2026-3294: TP-Link RE305 Firmware

High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.

An authentication logic vulnerability in multiple TP-Link range extenders allows an unauthenticated attacker on an adjacent network to manipulate a login parameter and reset the administrator password due to insufficient validation. Successful exploitation allows an attacker to obtain full administrative control of the affected device, potentially impacting on confidentiality, integrity, and availability.

Affected products

  • TP-Link RE305 Firmware: before 20260515 (fixed in 20260515)
  • TP-Link RE360 Firmware: before 20260515 (fixed in 20260515)
  • TP-Link RE580D Firmware: before 20260515 (fixed in 20260515)
  • TP-Link RE650 Firmware: before 20260429 (fixed in 20260429)
  • TP-Link Tl-WA860RE Firmware: before 20260515 (fixed in 20260515)

Published 2026-05-22. Last modified 2026-07-23.