CVE-2023-50224
KEVmassAuthentication Bypass by Spoofing in TP-Link TL-WR841N Router Exposes Stored Credentials
CISA: TP-Link TL-WR841N Authentication Bypass by Spoofing Vulnerability
CVE-2023-50224 is an improper authentication flaw (CWE-290) in the httpd service of the TP-Link TL-WR841N router, which listens on TCP port 80 by default; it was reported through Trend Micro's Zero Day Initiative (ZDI-CAN-19899). A network-adjacent attacker with no credentials can send spoofed authentication data to the web interface, bypassing authentication and disclosing stored credentials (including credentials handled by the device's dropbearpwd component). The attacker gains access to sensitive stored credentials, which can be leveraged for further compromise of the router and connected networks; the flaw has high confidentiality impact but no integrity or availability impact (CVSS 6.5, adjacent-network vector). Owners of TL-WR841N routers are affected, and vendor CPE data additionally enumerates related TP-Link firmware products (e.g., MR6400, TL-WDR3600, TL-WDR4300, TL-WR740N series); no specific vulnerable version ranges were provided in the source data. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2025-09-03, confirming exploitation in the wild (ransomware use unknown), although no public PoC is known.
What to do: Apply firmware updates from TP-Link per vendor instructions as required by the CISA KEV listing (follow BOD 22-01 guidance), and because this is an older router line, verify whether your specific hardware revision still receives firmware, replacing or retiring devices that are end-of-life. Until patched, restrict the web management interface to trusted LAN segments, disable WAN-side/remote management on TCP port 80, and rotate admin and WAN credentials (e.g., PPPoE) that may have been disclosed.
| tp-link tl-wr841n firmware | — |
| tp-link mr6400 firmware | — |
| tp-link tl-wdr3600 firmware | — |
| tp-link tl-wdr4300 firmware | — |
| tp-link wdr3500 firmware | — |
| tp-link tl-wr710n firmware | — |
| tp-link tl-wr740n firmware | — |
| tp-link tl-wr741nd firmware | — |
| tp-link tl-wr743nd firmware | — |
| tp-link wr749n firmware | — |
| tp-link mr3420 firmware | — |
| tp-link wr1043nd firmware | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of TP-Link TL-WR841N routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the httpd service, which listens on TCP port 80 by default. The issue results from improper authentication. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. Was ZDI-CAN-19899.
- Affected
- TP-Link TL-WR841N
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- tp-link
- Products
- tl-wr841n firmware, mr6400 firmware, tl-wdr3600 firmware, tl-wdr4300 firmware, wdr3500 firmware, tl-wr710n firmware, tl-wr740n firmware, tl-wr741nd firmware, tl-wr743nd firmware, wr749n firmware, mr3420 firmware, wr1043nd firmware
- Weakness
- CWE-290
- Vector
- CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N