Vulnerability record · CVE-2020-24363 · published 31 August 2020
CVE-2020-24363: TP-Link TL-WA855RE missing authentication allows factory reset
Tp Link · Tl Wa855re Firmware
TP-Link TL-WA855RE V5 firmware 20200415-rel37464 accepts a TDDP_RESET POST request without authentication, letting anyone on the same network trigger a factory reset and reboot. After the reset the attacker can set a new administrative password, taking over the device. The flaw is a missing authentication check on a critical function (CWE-306).
Description
TP-Link TL-WA855RE V5 20200415-rel37464 devices allow an unauthenticated attacker (on the same network) to submit a TDDP_RESET POST request for a factory reset and reboot. The attacker can then obtain incorrect access control by setting a new administrative password.
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityThe flaw allows unauthenticated full device takeover from the local network and is listed in CISA KEV, though it requires adjacency and affects a single end-of-line access point model.
What it is
TP-Link TL-WA855RE V5 firmware 20200415-rel37464 accepts a TDDP_RESET POST request without authentication, letting anyone on the same network trigger a factory reset and reboot. After the reset the attacker can set a new administrative password, taking over the device. The flaw is a missing authentication check on a critical function (CWE-306).
Impact
An attacker on the same network gains full administrative control of the device by resetting it and setting a new admin password, and can disrupt availability through the forced reboot.
Attack surface
Reachable over the adjacent network via a crafted TDDP_RESET POST request; no authentication and no user interaction are required, but the attacker must be on the same network segment (CVSS AV:A).
Exploitation
CVE-2020-24363 was added to CISA KEV on 2025-09-02, indicating known exploitation, and EPSS gives a 30-day probability of 0.207 (97.4th percentile). No ransomware campaign use is documented.
What to do
- Update TL-WA855RE V5 firmware to the latest release from TP-Link's support page; if no fixed firmware exists, discontinue use of the device per CISA guidance.
- Segment or isolate the device on a dedicated network or VLAN so untrusted hosts cannot reach its management interface.
- Restrict access to the device's web and TDDP services to trusted management hosts only.
- Monitor for unexpected factory resets or admin password changes and re-secure the device if one occurs.
Detection
- Alert on TDDP_RESET POST requests or other TDDP traffic to the device from hosts other than the management station.
- Monitor device logs and network telemetry for unexpected reboots or factory resets followed by administrative login or password change.
- Baseline the device's admin password and configuration and alert on out-of-band changes.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2020-24363 to the Known Exploited Vulnerabilities catalog on 2 September 2025 as "TP-link TL-WA855RE Missing Authentication for Critical Function Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 23 September 2025.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://malwrforensics.com/en/2020/08/31/cve-2020-24363-tl-wa855re-v5-advisory/ | Third Party Advisory |
| https://pastebin.com/VjHM4UiA | Third Party Advisory |
| https://www.tp-link.com/us/support/download/tl-wa855re/#Firmware | Product |
| http://malwrforensics.com/en/2020/08/31/cve-2020-24363-tl-wa855re-v5-advisory/ | Third Party Advisory |
| https://pastebin.com/VjHM4UiA | Third Party Advisory |
| https://www.tp-link.com/us/support/download/tl-wa855re/#Firmware | Product |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-24363 | US Government Resource |
Track CVE-2020-24363 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-24363), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.