CVE-2026-3294
An authentication logic vulnerability in multiple TP-Link range extenders allows an unauthenticated attacker on an adjacent network to manip
CVSS
8.8
Alto
EPSS
0.4%
p34
KEV
—
Exploit Today
10
0-100
Publicado: 22 may 2026 · Última mod.: 23 jul 2026 · CWE-20 · CWE-862
0.4%EPSS · 30 días0.4%
2026-08-252026-09-22
An authentication logic vulnerability in multiple TP-Link range extenders allows an unauthenticated attacker on an adjacent network to manipulate a login parameter and reset the administrator password due to insufficient validation. Successful exploitation allows an attacker to obtain full administrative control of the affected device, potentially impacting on confidentiality, integrity, and availability.
- www.tp-link.comhttps://www.tp-link.com/en/support/download/re305/v1/#Firmware
- www.tp-link.comhttps://www.tp-link.com/en/support/download/re360/v1/#Firmware
- www.tp-link.comhttps://www.tp-link.com/en/support/download/re580d/#Firmware
- www.tp-link.comhttps://www.tp-link.com/en/support/download/re650/v1/#Firmware
- www.tp-link.comhttps://www.tp-link.com/en/support/download/tl-wa860re/v4/#Firmware
- www.tp-link.comhttps://www.tp-link.com/us/support/download/re305/v1/#Firmware
- www.tp-link.comhttps://www.tp-link.com/us/support/download/re360/v1/#Firmware
- www.tp-link.comhttps://www.tp-link.com/us/support/download/re580d/#Firmware
- www.tp-link.comhttps://www.tp-link.com/us/support/download/re650/v1/#Firmware
- www.tp-link.comhttps://www.tp-link.com/us/support/download/tl-wa860re/v4/#Firmware
- www.tp-link.comhttps://www.tp-link.com/us/support/faq/5101/
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-958975.5 MED—
———A security vulnerability has been detected in Dask up to 2026.8.0. This affects the function from_npy_stack of the file dask/array/core.py of the component Loader. Such manipulation leads to deserialization. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.1hCVE-2026-181566.5 MED—
———IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to bypass security controls by forging user identities due to improper authorization.4hCVE-2026-181326.5 MED—
———IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to perform unauthorized payment mutation actions due to missing authorization.4hCVE-2026-176187.3 ALT—
———IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote unauthenticated attacker to view and modify sensitive information and cause a denial of service due to improper authorization.4hCVE-2026-77426——
———Unleash is an open-source feature management platform. Prior to 8.0.3, the Unleash admin API contains five authorization vulnerabilities. POST /api/admin/segments/strategies assigns the Promise returned by hasPermission without awaiting it, allowing authenticated users to modify segment assignments without UPDATE_FEATURE_STRATEGY permission for the target project and environment. GET /api/admin/projects/:projectId/features/:featureName/environments/:environment/variants does not bind the requested feature to projectId, allowing cross-project variant configuration disclosure. GET .../strategies/:strategyId uses strategyId without validating the project and feature context, allowing cross-project strategy configuration disclosure. getEnvironmentInfo does not validate that the requested feature belongs to the supplied project, allowing cross-project environment information disclosure. PUT /:projectId/tags accepts feature identifiers without verifying that they belong to the URL project, allowing cross-project tag modification. This issue is fixed in version 8.0.3.5hCVE-2026-63628——
———mppx is a TypeScript interface for machine payments protocol. Prior to 0.8.2, the fee-payer cosigning path in src/tempo/internal/fee-payer.ts copied a client-supplied access_list from a 0x78 FeePayerEnvelope without validating its length or contents. Because EIP-2930 access-list entries consume intrinsic gas even when the listed addresses are never used, a client could add fabricated address-only entries and cause the server fee_payer wallet to pay unnecessary transaction fees. The demonstrated 180-entry list remained within the 500,000 gas policy cap, 16 KB header limit, and RPC simulation budget while increasing the fee by approximately 9.4 times. This issue is fixed in version 0.8.2.6h