ZeroHour

CVE-2020-24363

KEVmass1

Missing Authentication in TP-Link TL-WA855RE Allows Unauthenticated Factory Reset

CISA: TP-link TL-WA855RE Missing Authentication for Critical Function Vulnerability

CVSS 3.1
8.8 high
EPSS
21%p97
Published
()
KEV added
AI analysis

CVE-2020-24363 is a missing-authentication flaw (CWE-306) in the TP-Link TL-WA855RE Wi-Fi range extender, where the critical TDDP reset function can be invoked without any credentials. An unauthenticated attacker who is on the same network as the device can send a TDDP_RESET POST request, forcing a factory reset and reboot. After the reset, the attacker can set a new administrative password, taking over the extender and gaining incorrect access control. Only TP-Link TL-WA855RE devices are listed as affected, and many of these units are end-of-life or end-of-service. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2025-09-02, confirming exploitation in the wild, and EPSS assigns a 20.7% probability of exploitation in the next 30 days (97th percentile).

What to do: Inventory networks for TL-WA855RE extenders; if a firmware update is available from TP-Link, apply it, otherwise follow the KEV required action and discontinue use or replace the device, especially since many units are EoL/EoS. As interim mitigation, restrict or segment LAN access to the extender, since exploitation requires the attacker to be on the same network. Given the KEV listing and 20.7% EPSS, treat remediation as time-sensitive under BOD 22-01 guidance.

Affected
TP-Link TL-WA855RE
Estimated exposure
mass≈1M devices in use (long-running best-selling consumer Wi-Fi range extender) — The TL-WA855RE was a top-selling consumer Wi-Fi range extender at major retailers for years, implying an installed base on the order of a million units, though many may have been retired given the product is EoL/EoS; the LAN-side nature of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

TP-Link TL-WA855RE V5 20200415-rel37464 devices allow an unauthenticated attacker (on the same network) to submit a TDDP_RESET POST request for a factory reset and reboot. The attacker can then obtain incorrect access control by setting a new administrative password.

CISA Known Exploited Vulnerability
Affected
TP-Link TL-WA855RE
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
tp-link
Products
tl-wa855re firmware
Weakness
CWE-306
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news