Exploited Known exploited (KEV) CVE-2020-24363

TP-Link TL-WA855RE missing authentication (CVE-2020-24363) — a device with no route to a fix, listed five years on

TP-Link TL-WA855RE Added to KEV Sep 2, 2025 Federal remediation due 2025-09-23

A home range extender where someone on the same network can trigger a factory reset without authenticating, and then set the administrative password. The catalog notes the product may have reached end of life or end of service and advises discontinuing its use.

Key facts

  • CVE IDCVE-2020-24363
  • Affected (vendor / product)TP-Link TL-WA855RE
  • CWECWE-306
  • ExploitationListed in CISA KEV (exploitation confirmed)
  • Remediation due2025-09-23 (U.S. federal civilian agencies, BOD 22-01)

Key points

  • A home range extender with missing authentication for a critical function (CWE-306).
  • An unauthenticated party on the same network is described as able to trigger a factory reset and reboot.
  • After the reset, a new administrative password can be set, yielding incorrect access control.
  • The catalog notes possible end of life or end of service and advises discontinuing use, so no update resolves it.
  • Numbered in 2020 and listed 2 September 2025, five years apart; 292 (17.2%) of the 1,694 records this site holds as of 2026-09-04 show a gap of three to five years.

1Not from outside, but from within the same network

The description states that the attacker is on the same network. This is not something that arrives directly from beyond the perimeter. That does not make it light. A wireless network in a home or a small office holds visitors' phones, devices someone carried in, and appliances whose behavior nobody watches. If being on the same network is enough, the condition is satisfied in exactly the places least likely to notice.

The aspectAn attack arriving from outsideAn attack from inside the same network
The premiseThe target must be exposed externallyGetting onto the same wireless network suffices
DetectabilityExternal scanning finds itNothing finds it unless internal devices are inventoried
Direction of defenseReduce exposureKnow what is on the network and segment it

2The reset itself becomes the technique

Restoring factory settings exists to rescue the user. When configuration goes wrong, there has to be a reliable way back. But if that exit lacks authentication, resetting becomes the first move of an attack. A device that has just been reset comes up with no administrative password set. Whoever reaches it first becomes its administrator. Nothing is broken; the device is made to be born again into someone else's hands.

3No route to a fix

Weakness recorded for this entryCWE-306Missing authentication for a critical function, shared by 41 (2.4%) of the 1,694 records this site holds as of 2026-09-04
Entries whose vendor is TP-Link, of those same 1,6946Consumer and small-office equipment appears too
Entries listed three to five years after numbering, of those same 1,69429217.2% of the total

The catalog notes that the product may have reached end of life or end of service, and advises discontinuing use. There is, in other words, no update to apply. Corporate asset management tracks equipment lifetimes; in a home or a small office, a device stays in service as long as it powers on. This is where the life of a vulnerability outlasts the life of the product.

4The five-year interval

The identifier dates from 2020 and the listing from 2025, five years apart. Of those same 1,694 records, 292 (17.2%) were listed three to five years after numbering. Sometimes exploitation takes that long to confirm; sometimes it is confirmed and prioritized later. Either way, age does not make a disclosed vulnerability safe.

Why it matters

An exit built for safety becomes an entrance when it lacks authentication. Reset and recovery functions must work when everything else is broken, which is exactly why their protection tends to be thin. Add a product past its service life and the update route disappears, leaving discontinuation as the only remedy. In small environments, where a device stays in use as long as it powers on, that shape of risk persists longest.

FAQ

Is it safe if the attacker must be on the same network?
Home and small-office wireless networks carry visitors' devices and equipment brought in by others. It is safer to assume the condition is easily met.
Why is a reset dangerous?
A device that has just been reset comes up with no administrative password set, so whoever configures it first becomes its administrator.
Does updating fix it?
The catalog notes possible end of life or end of service and advises discontinuing use. Confirm applicability with vendor sources.

Sources (primary)

This article is an independent organization based on the U.S. official data below. Always verify the exact, latest details and applicability with the official and vendor sources.

#Vulnerabilities#KEV#Security#Consumer devices#End of life
Disclaimer: This site independently summarizes and classifies information based on official data sources. Always verify the latest and accurate information with the official sources. Content on finance, health, legal, and security is information, not advice. This site is not an official website of the U.S. government.