Junglewise Threat Intelligence

CVE-2020-24363: TP-Link TL-WA855RE missing authentication for factory reset

CVE-2020-24363 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2025-09-02

Vendors: TP-Link.

Executive brief

A vulnerability in the TP-Link TL-WA855RE Wi-Fi range extender allows an unauthorized person on the same network to remotely reset the device to its factory settings. By forcing a reset, an attacker can then set their own administrative password, effectively taking full control of the device. This can lead to a complete loss of network privacy and allow the attacker to intercept or redirect internet traffic.

Technical details

The TP-Link TL-WA855RE (specifically V5) fails to require authentication for critical functions handled via the Test and Detection Data Protocol (TDDP). An unauthenticated attacker on the same local network or Wi-Fi segment can send a crafted 'TDDP_RESET' POST request to the device. This triggers a factory reset and reboot, clearing existing credentials. The attacker can then access the setup interface to establish a new administrative password, granting them full control over the device configuration. This vulnerability is confirmed to have been exploited in the wild.

Affected products

  • TP-Link TL-WA855RE firmware V5 versions up to (excluding) 200731

Timeline

  • 2020-08-31: disclosed
  • 2020-08-31: advisory
  • 2025-09-02: kev added: Added to CISA Known Exploited Vulnerabilities catalog.