Skip to content
COOEY

EXPOSURES › CVE-2020-24363

CVE-2020-24363

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2025-09-02 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-24363 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 exploited-in-wildunpatchedrce

TP-Link TL-WA855RE exposed to unauthenticated attacks via unpatched command injection flaw

TP-Link's TL-WA855RE routers, despite being end-of-life or end-of-service, remain vulnerable to unauthenticated attackers who can reset and reboot the device, potentially setting new admin passwords. Users should cease using these products immediately.

Shame score — Unpatched critical command injection flaw leading to unauthenticated attacks

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

TP-link TL-WA855RE contains a missing authentication for critical function vulnerability. This vulnerability could allow an unauthenticated attacker (on the same network) to submit a TDDP_RESET POST request for a factory reset and reboot. The attacker can then obtain incorrect access control by setting a new administrative password. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.