CVE-2020-24363
KEVmass1Missing Authentication in TP-Link TL-WA855RE Allows Unauthenticated Factory Reset
CISA: TP-link TL-WA855RE Missing Authentication for Critical Function Vulnerability
CVE-2020-24363 is a missing-authentication flaw (CWE-306) in the TP-Link TL-WA855RE Wi-Fi range extender, where the critical TDDP reset function can be invoked without any credentials. An unauthenticated attacker who is on the same network as the device can send a TDDP_RESET POST request, forcing a factory reset and reboot. After the reset, the attacker can set a new administrative password, taking over the extender and gaining incorrect access control. Only TP-Link TL-WA855RE devices are listed as affected, and many of these units are end-of-life or end-of-service. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2025-09-02, confirming exploitation in the wild, and EPSS assigns a 20.7% probability of exploitation in the next 30 days (97th percentile).
What to do: Inventory networks for TL-WA855RE extenders; if a firmware update is available from TP-Link, apply it, otherwise follow the KEV required action and discontinue use or replace the device, especially since many units are EoL/EoS. As interim mitigation, restrict or segment LAN access to the extender, since exploitation requires the attacker to be on the same network. Given the KEV listing and 20.7% EPSS, treat remediation as time-sensitive under BOD 22-01 guidance.
| TP-Link TL-WA855RE | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
TP-Link TL-WA855RE V5 20200415-rel37464 devices allow an unauthenticated attacker (on the same network) to submit a TDDP_RESET POST request for a factory reset and reboot. The attacker can then obtain incorrect access control by setting a new administrative password.
- Affected
- TP-Link TL-WA855RE
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- tp-link
- Products
- tl-wa855re firmware
- Weakness
- CWE-306
- Vector
- CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H