U.S. CISA adds TP-Link Archer C7(EU) and TL-WR841N flaws to its Known Exploited Vulnerabilities catalog
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-50224 | Authentication Bypass by Spoofing in TP-Link TL-WR841N Router Exposes Stored Credentials CVE-2023-50224 is an improper authentication flaw (CWE-290) in the httpd service of the TP-Link TL-WR841N router, which listens on TCP port 80 by default; it was reported through Trend Micro's Zero Day Initiative (ZDI-CAN-19899). A network-adjacent attacker with no credentials can send spoofed authentication data to the web interface, bypassing authentication and disclosing stored credentials (including credentials handled by the device's dropbearpwd component). The attacker gains access to sensitive stored credentials, which can be leveraged for further compromise of the router and connected networks; the flaw has high confidentiality impact but no integrity or availability impact (CVSS 6.5, adjacent-network vector). Owners of TL-WR841N routers are affected, and vendor CPE data additionally enumerates related TP-Link firmware products (e.g., MR6400, TL-WDR3600, TL-WDR4300, TL-WR740N series); no specific vulnerable version ranges were provided in the source data. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2025-09-03, confirming exploitation in the wild (ransomware use unknown), although no public PoC is known. Do: Apply firmware updates from TP-Link per vendor instructions as required by the CISA KEV listing (follow BOD 22-01 guidance), and because this is an older router line, verify whether your specific hardware revision still receives firmware, replacing or retiring devices that are end-of-life. Until patched, restrict the web management interface to trusted LAN segments, disable WAN-side/remote management on TCP port 80, and rotate admin and WAN credentials (e.g., PPPoE) that may have been disclosed. | 6.5 | 16% | KEV |
| masslikely millions of deployed devices (tens of millions of TL-WR841N units shipped globally; tens of thousands of TP-Link routers visible in public internet… | |
| CVE-2025-9377 | OS Command Injection in TP-Link Archer C7 (EU) and TL-WR841N/ND (MS) Routers TP-Link Archer C7 (EU) and TL-WR841N/ND (MS) routers contain an OS command injection vulnerability (CWE-78) in the Parental Control page of the device's web management interface. By submitting crafted input through that page, an attacker can execute arbitrary operating-system commands on the router with device-level privileges. Users of these specific models are affected, and CISA notes the products may be end-of-life (EoL) and/or end-of-service (EoS), which may limit the availability of fixes. The flaw was added to CISA's KEV catalog on 2025-09-03, indicating known active exploitation in the wild; no public proof-of-concept is known and ransomware use has not been confirmed. EPSS estimates a 33.5% probability of exploitation within the next 30 days (98th percentile), a relatively high likelihood given the vulnerability is unscored. Do: Inventory networks for Archer C7 (EU) and TL-WR841N/ND (MS) routers and apply the latest firmware from TP-Link if an update is offered for the specific hardware variant. Because the devices may be EoL/EoS and a patch may not be available, CISA's required action is to apply vendor mitigations (or BOD 22-01 guidance for federal agencies) or discontinue use of the product; as interim mitigation, disable WAN-side/remote web management, restrict the admin interface to trusted LAN access, and use strong administrator credentials. | 8.6 | 34% | KEV |
| mass≈1–10 million deployed units combined across the two affected model lines (estimate) |
Full article307 words · extracted from securityaffairs.com · click to collapse
Pierluigi Paganini
September 04, 2025

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds TP-Link Archer C7(EU) and TL-WR841N flaws to its Known Exploited Vulnerabilities catalog.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added TP-Link Archer C7(EU) and TL-WR841N flaws to its Known Exploited Vulnerabilities (KEV) catalog.
Below are the descriptions for these flaws:
- CVE-2023-50224 (CVSS score of 6.5) TP-Link TL-WR841N Authentication Bypass by Spoofing Vulnerability
- CVE-2025-9377 (CVSS score of 8.6) TP-Link Archer C7(EU) and TL-WR841N/ND(MS) OS Command Injection Vulnerability
CVE-2023-50224 is a TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure vulnerability. The flaw resides in the httpd service (port 80) that allows unauthenticated, network-adjacent attackers to disclose stored credentials.
“This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of TP-Link TL-WR841N routers. Authentication is not required to exploit this vulnerability.” reads the advisory.
“The specific flaw exists within the httpd service, which listens on TCP port 80 by default. The issue results from improper authentication. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise.”
The researchers Aleksandar Djurdjevic ‘revengsmK’ disclosed the flaw through the Zero Day initiative.
CVE-2025-9377 is an authenticated RCE flaw that affects TP-Link Archer C7(EU) V2 (pre-241108) and TL-WR841N/ND(MS) V9 (pre-241108).
Both devices are End of Life and the vendor urges customers to replace them or apply the patch.
According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.
Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure.
CISA orders federal agencies to fix the vulnerabilities by September 24, 2025.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, cisa)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/181886/hacking/u-s-cisa-adds-tp-link-archer-c7eu-and-tl-wr841n-flaws-to-its-known-exploited-vulnerabilities-catalog.html