← Back to CVE List
Vulnerability Intelligence Report
TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure Vulnerability

CVE-2023-50224

TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of TP-Link TL-WR841N routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the httpd service, which listens on TCP port 80 by default. The issue results from improper authentication. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. Was ZDI-CAN-19899.

CISA KEV SSVC: Active Exploitation
CVSS Base Score
6.5
MEDIUM
Exploitability:2.9
Impact Score:3.6
EPSS Probability:17.45%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-290 ↗CWE-290: Authentication Bypass by Spoofing

Affected Products & Versions

Vendor Product Affected Versions
TP-Link TL-WR841N 3.16.9 build 200409 (affected), V8 (affected), V9 (affected), V10 (affected), V11 (affected), V11_211209 (unaffected), V12 (affected), V12_230317 (unaffected)
TP-Link TL-WR841ND V8 (affected), V9 (affected), V10 (affected), V11 (affected), V11_211209 (unaffected), V12 (affected), V12_230317 (unaffected)
TP-Link TL-MR6400 V1 (affected), V2 (affected)
TP-Link Archer C5 V2 (affected)
TP-Link Archer C7 V2 (affected), V2_241108 (unaffected), V3 (affected)
TP-Link TL-WDR3600 V2 (affected)
TP-Link TL-WDR4300 V1 (affected)
TP-Link TL-WDR3500 V2 (affected)
TP-Link TL-WR740N V4 (affected), V5 (affected), V6 (affected), V7 (affected)
TP-Link TL-WR741ND V4 (affected), V5 (affected), V6 (affected)
TP-Link TL-WR749N BR 6.0 (affected), BR 7.0 (affected)
TP-Link TL-MR3420 V2 (affected), V3 (affected), V4 (affected)
TP-Link TL-WR1043ND V2 (affected), V3 (affected), V4 (affected)
TP-Link TL-WR1045ND RU V2 (affected)
TP-Link TL-WR840N V2 (affected), V3 (affected)
TP-Link TL-WR842N V2 (affected), V3 (affected), V4 (affected)
TP-Link TL-WR842ND V2 (affected), V3 (affected), V4 (affected)
TP-Link TL-WR845N V1 (affected), V2 (affected)
TP-Link TL-WR941ND V5 (affected), V6 (affected), V6_220610 (unaffected)
TP-Link TL-WR945N V1 (affected)
TP-Link TL-WA801ND V3 (affected), V4 (affected)
TP-Link TL-WA901ND V3 (affected), V4 (affected), V4_201030 (unaffected), V5 (affected), V5_201030 (unaffected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

CISA KEV
ACTIVE IN CATALOG
EPSS Score
17.450%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityZero Day Initiative · Bug Bounty Provider · Japan
Reserved2023-12-05T16:15:17
Published2024-05-03T02:14:42
Patch Date2023-12-19
Last Updated2026-09-02T17:58:31

LINK COPIED TO CLIPBOARD