CVE-2020-24363: TP-link TL-WA855RE Missing Authentication for Critical Function Vulnerability
TP-link TL-WA855RE contains a missing authentication for critical function vulnerability. This vulnerability could allow an unauthenticated attacker (on the same network) to submit a TDDPRESET POST request for a factory reset and reboot. The attacker can then obtain incorrect access control by setting a new administrative password. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.
Other sources
TP-Link TL-WA855RE V5 20200415-rel37464 devices allow an unauthenticated attacker (on the same network) to submit a TDDPRESET POST request for a factory reset and reboot. The attacker can then obtain incorrect access control by setting a new administrative password.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
TP-Link TL-WA855RE V5 20200415-rel37464from your environment.Discontinue product utilization (users should discontinue product utilization).
- Compensating control
Follow applicable BOD 22-01 guidance for cloud services.
Event History
Frequently Asked Questions
What is the severity of CVE-2020-24363?
CVE-2020-24363 is considered to be of medium severity due to its potential for unauthorized access.
How do I fix CVE-2020-24363?
To fix CVE-2020-24363, you should update the firmware of the TP-Link TL-WA855RE to the latest version provided by TP-Link.
Who is affected by CVE-2020-24363?
Devices running the TP-Link TL-WA855RE with firmware version 20200415 are affected by CVE-2020-24363.
What type of attack does CVE-2020-24363 enable?
CVE-2020-24363 enables an unauthenticated attacker on the same network to reset the device and potentially gain inappropriate access.
Can CVE-2020-24363 be exploited remotely?
No, CVE-2020-24363 requires the attacker to be on the same local network as the affected device.