CVE-2020-24363
9.5 CISA KEVTP-Link · TL-WA855RE
TP-Link TL-WA855RE devices allow an unauthenticated local attacker to trigger a factory reset via a TDDP_RESET request, enabling them to set a new administrative password and gain full device control.
Executive summary
This critical vulnerability in TP-Link TL-WA855RE extenders allows unauthenticated attackers to gain administrative control through a factory reset, and it is currently being exploited in the wild.
Vulnerability
This flaw involves missing authentication for a critical function, specifically allowing an unauthenticated attacker on the same network to submit a TDDP_RESET POST request. This action forces a factory reset and reboot, which subsequently permits the attacker to define a new administrative password.
Business impact
The exploitation of this vulnerability results in a total compromise of the affected device, allowing an attacker to intercept traffic or pivot into the internal network. Given the CVSS score of 9.5, this represents a severe risk to network integrity and confidentiality. Because the device has reached end-of-life status, the risk of permanent, unpatchable exposure is high, potentially leading to unauthorized access and long-term surveillance of network communications.
Remediation
Immediate Action: Update the firmware to version TL-WA855RE(EU)_V5_200731 immediately if the device is still in use. Given the device has reached end-of-life, if this update is unavailable or insufficient, the primary remediation is to decommission and replace the hardware.
Proactive Monitoring: Monitor network traffic for unexpected TDDP_RESET requests or unauthorized configuration changes on network extenders. Ensure that management interfaces for network hardware are restricted to isolated management VLANs.
Compensating Controls: Implement strict network access control (NAC) to prevent unauthorized devices from connecting to the network segment where the extender resides. Disable the management interface of the device if it is accessible over the local network.
Exploitation status
Public Exploit Available: Yes, an ExploitDB entry exists for this vulnerability.
Analyst recommendation
Due to the confirmed active exploitation and the critical severity of this vulnerability, organizations must prioritize the mitigation of affected TP-Link devices. If firmware updates cannot be applied or the device has reached end-of-life, the device should be removed from the network immediately to prevent unauthorized administrative access and potential network-wide compromise.