TP-Link TL-WA855RE missing authentication (CVE-2020-24363) — a device with no route to a fix, listed five years on
A home range extender where someone on the same network can trigger a factory reset without authenticating, and then set the administrative password. The catalog notes the product may have reached end of life or end of service and advises discontinuing its use.
Key facts
- CVE IDCVE-2020-24363
- Affected (vendor / product)TP-Link TL-WA855RE
- CWECWE-306
- ExploitationListed in CISA KEV (exploitation confirmed)
- Remediation due2025-09-23 (U.S. federal civilian agencies, BOD 22-01)
Key points
- A home range extender with missing authentication for a critical function (CWE-306).
- An unauthenticated party on the same network is described as able to trigger a factory reset and reboot.
- After the reset, a new administrative password can be set, yielding incorrect access control.
- The catalog notes possible end of life or end of service and advises discontinuing use, so no update resolves it.
- Numbered in 2020 and listed 2 September 2025, five years apart; 292 (17.2%) of the 1,694 records this site holds as of 2026-09-04 show a gap of three to five years.
1Not from outside, but from within the same network
The description states that the attacker is on the same network. This is not something that arrives directly from beyond the perimeter. That does not make it light. A wireless network in a home or a small office holds visitors' phones, devices someone carried in, and appliances whose behavior nobody watches. If being on the same network is enough, the condition is satisfied in exactly the places least likely to notice.
2The reset itself becomes the technique
Restoring factory settings exists to rescue the user. When configuration goes wrong, there has to be a reliable way back. But if that exit lacks authentication, resetting becomes the first move of an attack. A device that has just been reset comes up with no administrative password set. Whoever reaches it first becomes its administrator. Nothing is broken; the device is made to be born again into someone else's hands.
3No route to a fix
The catalog notes that the product may have reached end of life or end of service, and advises discontinuing use. There is, in other words, no update to apply. Corporate asset management tracks equipment lifetimes; in a home or a small office, a device stays in service as long as it powers on. This is where the life of a vulnerability outlasts the life of the product.
4The five-year interval
The identifier dates from 2020 and the listing from 2025, five years apart. Of those same 1,694 records, 292 (17.2%) were listed three to five years after numbering. Sometimes exploitation takes that long to confirm; sometimes it is confirmed and prioritized later. Either way, age does not make a disclosed vulnerability safe.
Why it matters
An exit built for safety becomes an entrance when it lacks authentication. Reset and recovery functions must work when everything else is broken, which is exactly why their protection tends to be thin. Add a product past its service life and the update route disappears, leaving discontinuation as the only remedy. In small environments, where a device stays in use as long as it powers on, that shape of risk persists longest.
FAQ
Is it safe if the attacker must be on the same network?
Why is a reset dangerous?
Does updating fix it?
Sources (primary)
This article is an independent organization based on the U.S. official data below. Always verify the exact, latest details and applicability with the official and vendor sources.
- CISA KEV Catalog (known exploited list)
- NVD (CVE details / CVSS)
- Vendor / reference advisory
- Vendor / reference advisory
- This product uses data from the NVD API but is not endorsed or certified by the NVD. KEV data is CC0 (public domain).