TP-Link RE305
cpe:2.3:h:tp-link:re3000:*:*:*:*:*:*:*, +1 more
- < V1_20260515
A vulnerability in the authentication logic of several TP-Link range extenders enables an unauthenticated attacker on an adjacent network to manipulate a login parameter and reset the administrator password, exploiting inadequate validation. This exploitation grants full administrative control over the affected device, with potential repercussions for confidentiality, integrity, and availability.
Exploitation of this vulnerability allows for unauthorized password resets and administrative access on the affected device.
Users are advised to update to the latest firmware version available on the TP-Link official website. Specific download links for the updated firmware are provided in the TP-Link security advisory.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.