PT-2026-42832 · Tp Link · Range Extender

Job Jobse

·

Published

2026-05-22

·

Updated

2026-05-23

·

CVE-2026-3294

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TP-Link range extenders (affected versions not specified)
Description An authentication logic flaw allows an unauthenticated attacker on an adjacent network to reset the administrator password due to insufficient validation of a login parameter. Successful exploitation enables an attacker to gain full administrative control of the device, which may impact confidentiality, integrity, and availability.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-3294

Affected Products

Range Extender