CVE-2020-24363CISA KEVEPSS p97.2%

CVE-2020-24363TP-link TL-WA855RE Missing Authentication for Critical Function Vulnerability

TP-Link / TL-WA855RE

Description

TP-link TL-WA855RE contains a missing authentication for critical function vulnerability. This vulnerability could allow an unauthenticated attacker (on the same network) to submit a TDDP_RESET POST request for a factory reset and reboot. The attacker can then obtain incorrect access control by setting a new administrative password. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

Scoring

EPSS20.69% probability of exploitation · percentile 97.2% · 2026-06-18T12:00:27Z

CISA KEV entry

Added to KEV: 2025-09-02

(incoming)1

TypeTargetConfidenceTier
KEVEntryTP-link TL-WA855RE Missing Authentication for Critical Function Vulnerabilitykev-cve-2020-243630%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2026-0834
CVE
TP-Link TL-WR841N Authentication Bypass by Spoofing Vulnerability
CVE
CVE-2026-3294
CVE
CVE-2025-14737
CVE
CVE-2026-5039
CVE
TP-Link Multiple Routers Command Injection Vulnerability
Sourced from NVD + CISA KEV + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.