CVE-2023-50224 KEV
6.5
MEDIUM · CVSS 3.1 · EPSS 15.6% (pctl 97)
Patch first
On CISA KEV — known exploited in the wild, due 2025-09-24.
Description
TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of TP-Link TL-WR841N routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the httpd service, which listens on TCP port 80 by default. The issue results from improper authentication. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. Was ZDI-CAN-19899.
Scoring
| CVSS | 6.5 (MEDIUM, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
| EPSS | 15.56% — more likely to be exploited than 97% of all CVEs |
| Weakness | CWE-290 |
| On CISA KEV | yes — remediate by 2025-09-24 |
| Public exploit | none known |
| Published | 2024-05-03 |
| Last modified | 2026-09-03 |
CISA KEV
| Name | TP-Link TL-WR841N Authentication Bypass by Spoofing Vulnerability |
|---|---|
| Added | 2025-09-03 |
| Due | 2025-09-24 |
| Vendor / product | TP-Link / TL-WR841N |
| Ransomware use | none reported |
Affected (40)
| Vendor | Product |
|---|---|
| tp-link | mr3420 |
| tp-link | mr3420 firmware |
| tp-link | mr6400 |
| tp-link | mr6400 firmware |
| tp-link | tl-wdr3600 |
| tp-link | tl-wdr3600 firmware |
| tp-link | tl-wdr4300 |
| tp-link | tl-wdr4300 firmware |
| tp-link | tl-wr710n |
| tp-link | tl-wr710n firmware |
| tp-link | tl-wr740n |
| tp-link | tl-wr740n firmware |
| tp-link | tl-wr741nd |
| tp-link | tl-wr741nd firmware |
| tp-link | tl-wr743nd |
| tp-link | tl-wr743nd firmware |
| tp-link | tl-wr810n |
| tp-link | tl-wr810n firmware |
| tp-link | tl-wr840n |
| tp-link | tl-wr840n firmware |
| tp-link | tl-wr841n |
| tp-link | tl-wr841n firmware |
| tp-link | tl-wr841nd |
| tp-link | tl-wr841nd firmware |
| tp-link | wdr3500 |
| tp-link | wdr3500 firmware |
| tp-link | wr1043nd |
| tp-link | wr1043nd firmware |
| tp-link | wr1045nd |
| tp-link | wr1045nd firmware |
| tp-link | wr749n |
| tp-link | wr749n firmware |
| tp-link | wr802n |
| tp-link | wr802n firmware |
| tp-link | wr841hp |
| tp-link | wr841hp firmware |
| tp-link | wr842n |
| tp-link | wr842n firmware |
| tp-link | wr842nd |
| tp-link | wr842nd firmware |
References
- https://www.tp-link.com/en/support/download/tl-wr841n/v12/#Firmware
- https://www.tp-link.com/us/support/faq/5058/
- https://www.zerodayinitiative.com/advisories/ZDI-23-1808/
- https://www.tp-link.com/en/support/download/tl-wr841n/v12/#Firmware
- https://www.zerodayinitiative.com/advisories/ZDI-23-1808/
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-50224
→ the Explorer · watch your stack · NVD