๐Ÿ” CVE Alert

CVE-2023-50224

MEDIUM 6.5 โš ๏ธ CISA KEV

TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure Vulnerability

CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th

TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of TP-Link TL-WR841N routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the httpd service, which listens on TCP port 80 by default. The issue results from improper authentication. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. . Was ZDI-CAN-19899.

CWE CWE-290
Vendor tp-link
Product tl-wr841n
Published May 3, 2024
Last Updated Oct 21, 2025
โš ๏ธ Actively Exploited โ€” Act Now

Get instant alerts for tp-link tl-wr841n

This vulnerability is actively exploited in the wild. Set up free real-time alerts so you're first to know about threats like CVE-2023-50224.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected Versions

TP-Link / TL-WR841N
3.16.9 build 200409

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
zerodayinitiative.com: https://www.zerodayinitiative.com/advisories/ZDI-23-1808/ tp-link.com: https://www.tp-link.com/en/support/download/tl-wr841n/v12/#Firmware cisa.gov: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-50224