malwrforensics.com
http://malwrforensics.com/en/2020/08/31/cve-2020-24363-tl-wa855re-v5-advisory CVE-2020-24363
HIGHCISA KEV
TP-link TL-WA855RE Missing Authentication for Critical Function Vulnerability
Record summary
CVE-2020-24363 has a selected CVSS score of 8.8 (high); EIP currently links 1 catalogued exploit. CISA lists CVE-2020-24363 in KEV.
Description
TP-Link TL-WA855RE V5 20200415-rel37464 devices allow an unauthenticated attacker (on the same network) to submit a TDDP_RESET POST request for a factory reset and reboot. The attacker can then obtain incorrect access control by setting a new administrative password.
Description source: CVE List
Exploitation context
Known exploitation
- CISA KEV
- Listed · Sep 2, 2025 · CISA
- VulnCheck KEV
- Listed · Sep 2, 2025 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationActive
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 30, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
TL-WA855REBrowse TP-Link / TL-WA855RE | CISA | Version data not supplied | |
Proofs of concept
1Catalogued exploits
ExploitDBTP-Link TL-WA855RE V5_200415 - Device Reset Auth BypassExploitDB exploitby malwrforensicsNot analyzed1 file
References
5nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-24363 pastebin.com
https://pastebin.com/VjHM4UiA cisa.govGovernment resource
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-24363 tp-link.com
https://www.tp-link.com/us/support/download/tl-wa855re