← Vulnerability feed

Vulnerability record · CVE-2020-24363 · published 31 August 2020

CVE-2020-24363: TP-Link TL-WA855RE missing authentication allows factory reset

Tp Link · Tl Wa855re Firmware

TP-Link TL-WA855RE V5 firmware 20200415-rel37464 accepts a TDDP_RESET POST request without authentication, letting anyone on the same network trigger a factory reset and reboot. After the reset the attacker can set a new administrative password, taking over the device. The flaw is a missing authentication check on a critical function (CWE-306).

8.8 CVSS 3.1 High CISA KEV since 2 Sep 2025 EPSS 21% · top 2.5% CWE-306 · Missing authentication for critical function
8.8CVSS 3.1 base score, v2 8.3
21%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
7References
17 Jun 2026Last modified by NVD

Description

TP-Link TL-WA855RE V5 20200415-rel37464 devices allow an unauthenticated attacker (on the same network) to submit a TDDP_RESET POST request for a factory reset and reboot. The attacker can then obtain incorrect access control by setting a new administrative password.

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityThe flaw allows unauthenticated full device takeover from the local network and is listed in CISA KEV, though it requires adjacency and affects a single end-of-line access point model.

What it is

TP-Link TL-WA855RE V5 firmware 20200415-rel37464 accepts a TDDP_RESET POST request without authentication, letting anyone on the same network trigger a factory reset and reboot. After the reset the attacker can set a new administrative password, taking over the device. The flaw is a missing authentication check on a critical function (CWE-306).

Impact

An attacker on the same network gains full administrative control of the device by resetting it and setting a new admin password, and can disrupt availability through the forced reboot.

Attack surface

Reachable over the adjacent network via a crafted TDDP_RESET POST request; no authentication and no user interaction are required, but the attacker must be on the same network segment (CVSS AV:A).

Exploitation

CVE-2020-24363 was added to CISA KEV on 2025-09-02, indicating known exploitation, and EPSS gives a 30-day probability of 0.207 (97.4th percentile). No ransomware campaign use is documented.

What to do

  • Update TL-WA855RE V5 firmware to the latest release from TP-Link's support page; if no fixed firmware exists, discontinue use of the device per CISA guidance.
  • Segment or isolate the device on a dedicated network or VLAN so untrusted hosts cannot reach its management interface.
  • Restrict access to the device's web and TDDP services to trusted management hosts only.
  • Monitor for unexpected factory resets or admin password changes and re-secure the device if one occurs.

Detection

  • Alert on TDDP_RESET POST requests or other TDDP traffic to the device from hosts other than the management station.
  • Monitor device logs and network telemetry for unexpected reboots or factory resets followed by administrative login or password change.
  • Baseline the device's admin password and configuration and alert on out-of-band changes.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2020-24363 to the Known Exploited Vulnerabilities catalog on 2 September 2025 as "TP-link TL-WA855RE Missing Authentication for Critical Function Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 23 September 2025.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-24363 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.0CVE-2020-10916Tp-link tl-wa855re firmware improper authentication vulnerabilityThis vulnerability allows network-adjacent attackers to escalate privileges on affected installations of TP-Link TL-WA855RE Firmware Ver: 855rev4-up-…EPSS 1.1%8.8CVE-2026-67277MikroTik RouterOS btest missing authentication leaks kernel memory and crashes kernelRouterOS accepts a "related" btest connection before the primary session is authenticated, letting an unauthenticated client start an IPv4 UDP test. …KEVEPSS 1.6%analysed8.8CVE-2026-59822LiteLLM MCP endpoint auth bypass via OAuth2 passthrough fallbackLiteLLM's MCP Streamable HTTP endpoint, prior to 1.84.0, let an unauthenticated attacker send a fabricated Authorization header that triggered an OAu…KEVEPSS 0.84%analysed9.3CVE-2026-72529TrueConf Server missing authentication allows remote script executionTrueConf Server versions 5.3.X through 5.3.9, 5.4.X through 5.4.9, 5.5.X through 5.5.5, and earlier expose an undocumented function on port 4307/TCP …KEVEPSS 1.5%analysed9.8CVE-2026-46817Oracle E-Business Suite Payments missing authentication allows takeoverOracle Payments in Oracle E-Business Suite 12.2.3 through 12.2.15 contains an easily exploitable flaw in the File Transmission component. An unauthen…KEVEPSS 0.81%analysed9.8CVE-2026-56164Microsoft SharePoint Server missing authentication allows privilege elevationMicrosoft Office SharePoint Server contains a missing authentication flaw in a critical function (CWE-306), letting an unauthenticated attacker reach…KEVEPSS 1.0%analysed9.8CVE-2026-20253Splunk Enterprise PostgreSQL sidecar missing authentication allows file writesSplunk Enterprise 10.2 below 10.2.4 and 10.x below 10.0.7 expose a PostgreSQL sidecar service endpoint that lacks authentication controls. Any networ…KEVEPSS 97%analysed9.8CVE-2026-35273Oracle PeopleSoft PeopleTools missing authentication allows takeoverOracle PeopleSoft Enterprise PeopleTools (Updates Environment Management component) in versions 8.61 and 8.62 is missing authentication for a critica…KEVEPSS 9.4%analysed

Source: NIST National Vulnerability Database (record CVE-2020-24363), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.