CVE-2020-24363

HIGH(8.8)KEVErhöhtes Risiko

TP-link TL-WA855RE Missing Authentication for Critical Function Vulnerability

Beschreibung

TP-Link TL-WA855RE V5 20200415-rel37464 devices allow an unauthenticated attacker (on the same network) to submit a TDDP_RESET POST request for a factory reset and reboot. The attacker can then obtain incorrect access control by setting a new administrative password.

KEV-Informationen

Hersteller
TP-Link
Produkt
TL-WA855RE
Hinzugefügt am
2. September 2025
Fälligkeitsdatum
23. September 2025
Erforderliche Maßnahme
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS-Score

Vektorstring
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HIm Rechner öffnen
Angriffsvektor
ADJACENT_NETWORK
Angriffskomplexität
LOW
Erforderliche Privilegien
NONE
Benutzerinteraktion
NONE
Scope
UNCHANGED
Vertraulichkeitsauswirkung
HIGH
Integritätsauswirkung
HIGH
Verfügbarkeitsauswirkung
HIGH
Ausnutzbarkeitsscore
2.8
Auswirkungsscore
5.9

CWEs

Betroffene Produkte

HerstellerProduktVersion
tp-linktl-wa855re firmware< 200731

Mehrere CVSS-Bewertungen

Quelle: [email protected](Primary)
8.8
HIGH

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Quelle: 134c704f-9b21-4f2e-91b3-4a467353bcc0(Secondary)
8.8
HIGH

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Referenzen

CVSS-Score

8.8
HIGH(8.8)

EPSS-Score

EPSS-Score20.69%
EPSS-Perzentil97.3%

Daten

Veröffentlicht31. August 2020
Zuletzt geändert17. Juni 2026
StatusAnalyzed
CVSS-Versionv3.1

Hilfe beim Schwachstellenmanagement?

Unsere Sicherheitsexperten helfen Ihnen bei der Priorisierung und Behebung von Schwachstellen.