LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2020-24363: TP-link TL-WA855RE Missing Authentication for Critical Function Vulnerability

RBRecent Breaches Vulnerability Intelligence·Sep 2, 2025
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Sep 23, 2025
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2020-24363 to its Known Exploited Vulnerabilities catalog on Sep 2, 2025, with a federal patch deadline of Sep 23, 2025 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

TP-link TL-WA855RE contains a missing authentication for critical function vulnerability. This vulnerability could allow an unauthenticated attacker (on the same network) to submit a TDDP_RESET POST…

CVE-2020-24363 is a missing-authentication flaw in the TP-Link TL-WA855RE wireless range extender. An unauthenticated attacker already on the same local network can force a factory reset and reboot, then set a new administrative password and take control of the device. Because the product may be end-of-life or end-of-service, continued use leaves the device permanently exposed to this class of attack.

For IT and security teams the risk is straightforward: a compromised extender can serve as a foothold for further lateral movement, traffic interception, or persistent access on the LAN. Confirm all technical details against the vendor advisory before acting.

How it works

The vulnerability is classified as CWE-306 (Missing Authentication for Critical Function). The device accepts a TDDP_RESET POST request without requiring any credentials. An attacker who can reach the device on the local network simply submits that request; the extender performs a factory reset and reboots. Once the device is back online in its default state, the attacker can assign a new administrative password and thereby obtain full control.

No remote Internet exposure is required—only local-network reachability. The attack therefore depends on the attacker already being present on the same Layer-2 or Layer-3 segment (for example via a compromised client, guest Wi-Fi, or physical access). Specific request formats, ports, or firmware versions must be verified against the vendor advisory; public detail beyond the CISA summary is limited.

Am I affected? How to find it in your systems

The only product named in the advisory is the TP-Link TL-WA855RE range extender. These devices are typically deployed in homes, small offices, or branch locations to extend Wi-Fi coverage and appear on the network as wireless bridges or access points.

If the model is present and no vendor patch is listed, treat the device as vulnerable.

How to remediate

The CISA-required action is to apply mitigations per vendor instructions or, if mitigations are unavailable, to discontinue use of the product. Given the end-of-life / end-of-service status noted in the advisory, the practical remediation path for most organizations is immediate decommissioning.

Follow any additional guidance the vendor publishes; do not rely on community work-arounds that have not been validated.

If you can't patch immediately

When immediate replacement is not feasible, apply compensating controls that reduce the attack surface until the device can be retired.

These measures only buy time; they do not eliminate the underlying missing-authentication flaw.

If your data may have been exposed

Actively exploited local-network vulnerabilities can lead to broader compromise of credentials, traffic, or adjacent systems. If you suspect the extender was reset or reconfigured by an unauthorized party, treat any credentials or sessions that traversed the device as potentially exposed. Rotate those credentials, review adjacent host logs for lateral movement, and consider a free exposure scan of organizational email addresses against known breach data sets to determine whether related accounts have already appeared in public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedTP-Link · TL-WA855RE
WeaknessCWE-306
Added to CISA KEVSep 2, 2025
Federal patch deadlineSep 23, 2025
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities