MEDIUM🚩 CISA KEV⚡ EXPLOIT🇵🇱 Wersja polska

CVE-2023-50224

CVSS 6.5v3.0pub. 2024-05-03upd. 2026-09-03

TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of TP-Link TL-WR841N routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the httpd service, which listens on TCP port 80 by default. The issue results from improper authentication. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. Was ZDI-CAN-19899.

CVSS Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
  • Tp Link Archer C1900

    HW
    Tp-Link
    1.0
  • Tp Link Archer C1900 Firmware

    OS
    Tp-Link
    < 1_260428
  • Tp Link Archer C5

    HW
    Tp-Link
    2.0
  • Tp Link Archer C5 Firmware

    OS
    Tp-Link
    2_150130 – 2_260429 (excl.)
  • Tp Link Archer C7

    HW
    Tp-Link
    2.03.0
  • Tp Link Archer C7 Firmware

    OS
    Tp-Link
    3_1505082_131217 – 2_241108 (excl.)
  • Tp Link Mr3420

    HW
    Tp-Link
    2.03.04.0
  • Tp Link Mr3420 Firmware

    OS
    Tp-Link
    all versions
  • Tp Link Mr6400

    HW
    Tp-Link
    1.02.0
  • Tp Link Mr6400 Firmware

    OS
    Tp-Link
    all versions
  • Tp Link Tl Mr3020

    HW
    Tp-Link
    1.0
  • Tp Link Tl Mr3020 Firmware

    OS
    Tp-Link
    all versions
  • Tp Link Tl Mr3220

    HW
    Tp-Link
    2.0
  • Tp Link Tl Mr3220 Firmware

    OS
    Tp-Link
    all versions
  • Tp Link Tl Wdr3600

    HW
    Tp-Link
    2.0
  • Tp Link Tl Wdr3600 Firmware

    OS
    Tp-Link
    all versions
  • Tp Link Tl Wdr4300

    HW
    Tp-Link
    1
  • Tp Link Tl Wdr4300 Firmware

    OS
    Tp-Link
    all versions
  • Tp Link Tl Wr710n

    HW
    Tp-Link
    1.02.0
  • Tp Link Tl Wr710n Firmware

    OS
    Tp-Link
    all versions
  • Tp Link Tl Wr740n

    HW
    Tp-Link
    4.05.06.07.0
  • Tp Link Tl Wr740n Firmware

    OS
    Tp-Link
    all versions
  • Tp Link Tl Wr741nd

    HW
    Tp-Link
    2.04.056.0
  • Tp Link Tl Wr741nd Firmware

    OS
    Tp-Link
    all versions
  • Tp Link Tl Wr743nd

    HW
    Tp-Link
    2.0
  • Tp Link Tl Wr743nd Firmware

    OS
    Tp-Link
    all versions
  • Tp Link Tl Wr810n

    HW
    Tp-Link
    1.02.0
  • Tp Link Tl Wr810n Firmware

    OS
    Tp-Link
    all versions
  • Tp Link Tl Wr840n

    HW
    Tp-Link
    2.03.0
  • Tp Link Tl Wr840n Firmware

    OS
    Tp-Link
    all versions

CISA KEV — detailsi

Vendori
TP-Link
Producti
TL-WR841N
Added to KEVi
September 3, 2025
Remediation deadline (US Federal)i
September 24, 2025(overdue)
Required action (CISA)i

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CISA descriptioni

TP-Link TL-WR841N contains an authentication bypass by spoofing vulnerability within the httpd service, which listens on TCP port 80 by default, leading to the disclose of stored credentials. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

🔴
IMMEDIATE ACTION
Actively exploited in the wild (CISA KEV). Patch immediately.
CISA DEADLINE: 24 września 2025
CWE
References

Related vulnerabilities

CVE-2023-36355CRITICAL9.9PL ✓same product

Buffer overflow w routerze TP-Link TL-WR940N — podatność DoS

CVE-2023-27078CRITICAL9.8PL ✓same product

Command injection w TP-Link MR3020 — zdalne wykonanie kodu przez endpoint TFTP

CVE-2022-4498CRITICAL9.8PL ✓same product

Heap overflow w httpd routerów TP-Link Archer C5 i WR710N-V1 umożliwiający RCE

CVE-2022-25061CRITICAL9.8PL ✓same product

Command injection w TP-LINK TL-WR840N przez oal_setIp6DefaultRoute

CVE-2022-25060CRITICAL9.8PL ✓same product

Command injection w routerze TP-LINK TL-WR840N przez komponent oal_startPing