ZeroHour

CVE-2023-50224

KEVmass

Authentication Bypass by Spoofing in TP-Link TL-WR841N Router Exposes Stored Credentials

CISA: TP-Link TL-WR841N Authentication Bypass by Spoofing Vulnerability

CVSS 3.1
6.5 medium
EPSS
16%p97
Published
()
KEV added
AI analysis

CVE-2023-50224 is an improper authentication flaw (CWE-290) in the httpd service of the TP-Link TL-WR841N router, which listens on TCP port 80 by default; it was reported through Trend Micro's Zero Day Initiative (ZDI-CAN-19899). A network-adjacent attacker with no credentials can send spoofed authentication data to the web interface, bypassing authentication and disclosing stored credentials (including credentials handled by the device's dropbearpwd component). The attacker gains access to sensitive stored credentials, which can be leveraged for further compromise of the router and connected networks; the flaw has high confidentiality impact but no integrity or availability impact (CVSS 6.5, adjacent-network vector). Owners of TL-WR841N routers are affected, and vendor CPE data additionally enumerates related TP-Link firmware products (e.g., MR6400, TL-WDR3600, TL-WDR4300, TL-WR740N series); no specific vulnerable version ranges were provided in the source data. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2025-09-03, confirming exploitation in the wild (ransomware use unknown), although no public PoC is known.

What to do: Apply firmware updates from TP-Link per vendor instructions as required by the CISA KEV listing (follow BOD 22-01 guidance), and because this is an older router line, verify whether your specific hardware revision still receives firmware, replacing or retiring devices that are end-of-life. Until patched, restrict the web management interface to trusted LAN segments, disable WAN-side/remote management on TCP port 80, and rotate admin and WAN credentials (e.g., PPPoE) that may have been disclosed.

Affected
tp-link tl-wr841n firmware
tp-link mr6400 firmware
tp-link tl-wdr3600 firmware
tp-link tl-wdr4300 firmware
tp-link wdr3500 firmware
tp-link tl-wr710n firmware
tp-link tl-wr740n firmware
tp-link tl-wr741nd firmware
tp-link tl-wr743nd firmware
tp-link wr749n firmware
tp-link mr3420 firmware
tp-link wr1043nd firmware
Estimated exposure
masslikely millions of deployed devices (tens of millions of TL-WR841N units shipped globally; tens of thousands of TP-Link routers visible in public internet… — The TL-WR841N is one of the world's best-selling budget SOHO routers with tens of millions of units sold, and public internet-wide scan data shows tens of thousands of exposed TP-Link web management interfaces, so plausibly affected…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of TP-Link TL-WR841N routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the httpd service, which listens on TCP port 80 by default. The issue results from improper authentication. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. Was ZDI-CAN-19899.

CISA Known Exploited Vulnerability
Affected
TP-Link TL-WR841N
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
tp-link
Products
tl-wr841n firmware, mr6400 firmware, tl-wdr3600 firmware, tl-wdr4300 firmware, wdr3500 firmware, tl-wr710n firmware, tl-wr740n firmware, tl-wr741nd firmware, tl-wr743nd firmware, wr749n firmware, mr3420 firmware, wr1043nd firmware
Weakness
CWE-290
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news