Executive brief
A vulnerability in the TP-Link TL-WA855RE Wi-Fi range extender allows an unauthorized person on the same network to remotely reset the device to its factory settings. By forcing a reset, an attacker can then set their own administrative password, effectively taking full control of the device. This can lead to a complete loss of network privacy and allow the attacker to intercept or redirect internet traffic.
Technical details
The TP-Link TL-WA855RE (specifically V5) fails to require authentication for critical functions handled via the Test and Detection Data Protocol (TDDP). An unauthenticated attacker on the same local network or Wi-Fi segment can send a crafted 'TDDP_RESET' POST request to the device. This triggers a factory reset and reboot, clearing existing credentials. The attacker can then access the setup interface to establish a new administrative password, granting them full control over the device configuration. This vulnerability is confirmed to have been exploited in the wild.
Affected products
- TP-Link TL-WA855RE firmware V5 versions up to (excluding) 200731
Timeline
- 2020-08-31: disclosed
- 2020-08-31: advisory
- 2025-09-02: kev added: Added to CISA Known Exploited Vulnerabilities catalog.