← Back to browse · API

CVE-2020-24363

Severity
HIGH
CVSS
8.8
EPSS
0.20689
Risk score
67.44
CISA KEV
Yes
PoC
No
Published
2020-08-31
Modified
2025-10-21
First seen
2026-08-07
Aliases
EUVD-2020-17095, GHSA-339J-XV49-Q5P7
Products
TP-Link:TL-WA855RE, n/a:n/a n/a
Sources
cisa.gov CVE-2020-24363
euvd EUVD-2020-17095

Description

TP-Link TL-WA855RE V5 20200415-rel37464 devices allow an unauthenticated attacker (on the same network) to submit a TDDP_RESET POST request for a factory reset and reboot. The attacker can then obtain incorrect access control by setting a new administrative password.

References