CVE-2020-24363

HIGH KEV

TP-Link TL-WA855RE V5 - Privilege Escalation

Title source: llm

Description

TP-Link TL-WA855RE V5 20200415-rel37464 devices allow an unauthenticated attacker (on the same network) to submit a TDDP_RESET POST request for a factory reset and reboot. The attacker can then obtain incorrect access control by setting a new administrative password.

Exploits (1)

exploitdb WORKING POC
by malwrforensics · textwebappshardware
https://www.exploit-db.com/exploits/49092

Scores

CVSS v3 8.8
EPSS 0.1261
EPSS Percentile 94.0%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CISA KEV 2025-09-02
VulnCheck KEV 2025-09-02
ENISA EUVD EUVD-2020-17095
CWE
CWE-306
Status published
Products (1)
tp-link/tl-wa855re_firmware < 200731
Published Aug 31, 2020
KEV Added Sep 02, 2025
Tracked Since Feb 18, 2026