CISA Flags TP-Link Router Flaws CVE-2023-50224 and CVE-2025
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2020-24363 | Missing Authentication in TP-Link TL-WA855RE Allows Unauthenticated Factory Reset CVE-2020-24363 is a missing-authentication flaw (CWE-306) in the TP-Link TL-WA855RE Wi-Fi range extender, where the critical TDDP reset function can be invoked without any credentials. An unauthenticated attacker who is on the same network as the device can send a TDDP_RESET POST request, forcing a factory reset and reboot. After the reset, the attacker can set a new administrative password, taking over the extender and gaining incorrect access control. Only TP-Link TL-WA855RE devices are listed as affected, and many of these units are end-of-life or end-of-service. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2025-09-02, confirming exploitation in the wild, and EPSS assigns a 20.7% probability of exploitation in the next 30 days (97th percentile). Do: Inventory networks for TL-WA855RE extenders; if a firmware update is available from TP-Link, apply it, otherwise follow the KEV required action and discontinue use or replace the device, especially since many units are EoL/EoS. As interim mitigation, restrict or segment LAN access to the extender, since exploitation requires the attacker to be on the same network. Given the KEV listing and 20.7% EPSS, treat remediation as time-sensitive under BOD 22-01 guidance. | 8.8 | 21% | KEV |
| mass≈1M devices in use (long-running best-selling consumer Wi-Fi range extender) | |
| CVE-2023-50224 | Authentication Bypass by Spoofing in TP-Link TL-WR841N Router Exposes Stored Credentials CVE-2023-50224 is an improper authentication flaw (CWE-290) in the httpd service of the TP-Link TL-WR841N router, which listens on TCP port 80 by default; it was reported through Trend Micro's Zero Day Initiative (ZDI-CAN-19899). A network-adjacent attacker with no credentials can send spoofed authentication data to the web interface, bypassing authentication and disclosing stored credentials (including credentials handled by the device's dropbearpwd component). The attacker gains access to sensitive stored credentials, which can be leveraged for further compromise of the router and connected networks; the flaw has high confidentiality impact but no integrity or availability impact (CVSS 6.5, adjacent-network vector). Owners of TL-WR841N routers are affected, and vendor CPE data additionally enumerates related TP-Link firmware products (e.g., MR6400, TL-WDR3600, TL-WDR4300, TL-WR740N series); no specific vulnerable version ranges were provided in the source data. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2025-09-03, confirming exploitation in the wild (ransomware use unknown), although no public PoC is known. Do: Apply firmware updates from TP-Link per vendor instructions as required by the CISA KEV listing (follow BOD 22-01 guidance), and because this is an older router line, verify whether your specific hardware revision still receives firmware, replacing or retiring devices that are end-of-life. Until patched, restrict the web management interface to trusted LAN segments, disable WAN-side/remote management on TCP port 80, and rotate admin and WAN credentials (e.g., PPPoE) that may have been disclosed. | 6.5 | 16% | KEV |
| masslikely millions of deployed devices (tens of millions of TL-WR841N units shipped globally; tens of thousands of TP-Link routers visible in public internet… | |
| CVE-2025-9377 | OS Command Injection in TP-Link Archer C7 (EU) and TL-WR841N/ND (MS) Routers TP-Link Archer C7 (EU) and TL-WR841N/ND (MS) routers contain an OS command injection vulnerability (CWE-78) in the Parental Control page of the device's web management interface. By submitting crafted input through that page, an attacker can execute arbitrary operating-system commands on the router with device-level privileges. Users of these specific models are affected, and CISA notes the products may be end-of-life (EoL) and/or end-of-service (EoS), which may limit the availability of fixes. The flaw was added to CISA's KEV catalog on 2025-09-03, indicating known active exploitation in the wild; no public proof-of-concept is known and ransomware use has not been confirmed. EPSS estimates a 33.5% probability of exploitation within the next 30 days (98th percentile), a relatively high likelihood given the vulnerability is unscored. Do: Inventory networks for Archer C7 (EU) and TL-WR841N/ND (MS) routers and apply the latest firmware from TP-Link if an update is offered for the specific hardware variant. Because the devices may be EoL/EoS and a patch may not be available, CISA's required action is to apply vendor mitigations (or BOD 22-01 guidance for federal agencies) or discontinue use of the product; as interim mitigation, disable WAN-side/remote web management, restrict the admin interface to trusted LAN access, and use strong administrator credentials. | 8.6 | 34% | KEV |
| mass≈1–10 million deployed units combined across the two affected model lines (estimate) |
Full article341 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananSep 04, 2025Vulnerability / Network Security
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added two security flaws impacting TP-Link wireless routers to its Known Exploited Vulnerabilities (KEV) catalog, noting that there is evidence of them being exploited in the wild.
The vulnerabilities in question are listed below -
- CVE-2023-50224 (CVSS score: 6.5) - An authentication bypass by spoofing vulnerability within the httpd service of TP-Link TL-WR841N, which listens on TCP port 80 by default, leading to the disclosure of stored credentials in "/tmp/dropbear/dropbearpwd"
- CVE-2025-9377 (CVSS score: 8.6) - An operating system command injection vulnerability in TP-Link Archer C7(EU) V2 and TL-WR841N/ND(MS) V9 that could lead to remote code execution
According to information listed on the company's website, the following router models have reached end-of-life (EoL) status -
- TL-WR841N (versions 10.0 and 11.0)
- TL-WR841ND (version 10.0)
- Archer C7 (versions 2.0 and 3.0)
However, TP-Link has released firmware updates for the two vulnerabilities as of November 2024 owing to malicious exploitation activity.
"The affected products have reached their End-of-Service (EOS) and are no longer receiving active support, including security updates," the company said. "For enhanced protection, we recommend that customers upgrade to newer hardware to ensure optimal performance and security."
There are no public reports explicitly referencing the exploitation of the aforementioned vulnerabilities, but TP-Link, in an advisory updated last week, linked in-the-wild activity to a botnet known as Quad7 (aka CovertNetwork-1658), which has been leveraged by a China-linked threat actor codenamed Storm-0940 to conduct highly evasive password spray attacks.
In light of active exploitation, Federal Civilian Executive Branch (FCEB) agencies are being urged to apply the necessary mitigations by September 24, 2025, to secure their networks.
The development comes a day after CISA placed another high-severity security flaw impacting TP-Link TL-WA855RE Wi-Fi Ranger Extender products (CVE-2020-24363, CVSS score: 8.8) to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2025/09/cisa-flags-tp-link-router-flaws-cve.html