An authentication logic vulnerability in multiple TP-Link range extenders allows an unauthenticated attacker on an adjacent network to manipulate a login parameter and reset the administrator password due to insufficient validation. Successful exploitation allows an attacker to obtain full administrative control of the affected device, potentially impacting on confidentiality, integrity, and availability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 20260515CPE matchmatch criteria | cpe:2.3:o:tp-link:re305_firmware:*:*:*:*:*:*:*:* | ||
< 20260515CPE matchmatch criteria | cpe:2.3:o:tp-link:re360_firmware:*:*:*:*:*:*:*:* | ||
< 20260515CPE matchmatch criteria | cpe:2.3:o:tp-link:re580d_firmware:*:*:*:*:*:*:*:* | ||
< 20260429CPE matchmatch criteria | cpe:2.3:o:tp-link:re650_firmware:*:*:*:*:*:*:*:* | ||
< 20260515CPE matchmatch criteria | cpe:2.3:o:tp-link:tl-wa860re_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.