CVE-2020-24363
HIGH(8.8)KEVElevated Risk
TP-link TL-WA855RE Missing Authentication for Critical Function Vulnerability
Description
TP-Link TL-WA855RE V5 20200415-rel37464 devices allow an unauthenticated attacker (on the same network) to submit a TDDP_RESET POST request for a factory reset and reboot. The attacker can then obtain incorrect access control by setting a new administrative password.
KEV Information
CVSS Score
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HOpen in CalculatorAffected Products
| Vendor | Product | Version |
|---|---|---|
| tp-link | tl-wa855re firmware | < 200731 |
Multiple CVSS Assessments
Source: [email protected](Primary)
8.8
HIGH
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0(Secondary)
8.8
HIGH
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
References
- http://malwrforensics.com/en/2020/08/31/cve-2020-24363-tl-wa855re-v5-advisory/(Third Party Advisory)
- https://pastebin.com/VjHM4UiA(Third Party Advisory)
- https://www.tp-link.com/us/support/download/tl-wa855re/#Firmware(Product)
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-24363(US Government Resource)
Need Help With Vulnerability Management?
Our security experts can help you prioritize and remediate vulnerabilities effectively.