Description
An authentication logic vulnerability in multiple TP-Link range extenders allows an unauthenticated attacker on an adjacent network to manipulate a login parameter and reset the administrator password due to insufficient validation. Successful exploitation allows an attacker to obtain full administrative control of the affected device, potentially impacting on confidentiality, integrity, and availability.
Problem types
CWE-20 Improper Input Validation
Product status
Any version before V1_20260429
Any version before V1_20260515
Any version before V1_20260515
Any version before V4_20260515
Any version before V1_20260515
Credits
Job Jobse
References
www.tp-link.com/en/support/download/re650/v1/
www.tp-link.com/us/support/download/re650/v1/
www.tp-link.com/us/support/download/re305/v1/
www.tp-link.com/en/support/download/re305/v1/
www.tp-link.com/us/support/download/re360/v1/
www.tp-link.com/en/support/download/re360/v1/
www.tp-link.com/us/support/download/tl-wa860re/v4/
www.tp-link.com/en/support/download/tl-wa860re/v4/
www.tp-link.com/en/support/download/re580d/
www.tp-link.com/us/support/download/re580d/
www.tp-link.com/us/support/faq/5101/