SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2023-50224

TP-Link TL-WR841N Authentication Bypass by Spoofing Vulnerability

KEVMEDIUM 6.5EPSS 15.6%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 24 September 2025). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of TP-Link TL-WR841N routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the httpd service, which listens on TCP port 80 by default. The issue results from improper authentication. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. Was ZDI-CAN-19899.

CVSS 3.1
6.5 MEDIUMCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS
15.56% probability · 97th percentile
CISA KEV
Listed 3 September 2025 · due 24 September 2025
Weakness
CWE-290
Affected
tp-link/tl-wr841n firmware · tp-link/mr6400 firmware · tp-link/tl-wdr3600 firmware · tp-link/tl-wdr4300 firmware · tp-link/wdr3500 firmware · tp-link/tl-wr710n firmware · tp-link/tl-wr740n firmware · tp-link/tl-wr741nd firmware · tp-link/tl-wr743nd firmware · tp-link/wr749n firmware · tp-link/mr3420 firmware · tp-link/wr1043nd firmware · tp-link/wr1045nd firmware · tp-link/wr802n firmware · tp-link/tl-wr810n firmware · tp-link/tl-wr840n firmware · tp-link/wr841hp firmware · tp-link/tl-wr841nd firmware · tp-link/wr842n firmware · tp-link/wr842nd firmware · +16 more
Source
zdi-disclosures@trendmicro.com

CISA notes

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. https://www.tp-link.com/us/support/faq/4308/ ; https://nvd.nist.gov/vuln/detail/CVE-2023-50224

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.