Skip to main content
CISA Known Exploited Vulnerabilities

TP-Link TL-WR841N Authentication Bypass by Spoofing Vulnerability is confirmed as actively exploited and is listed in the CISA KEV catalog.

Added to KEV
2025-09-03
Remediation due
2025-09-24

Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CISA notes
https://www.tp-link.com/us/support/faq/4308/ ; https://nvd.nist.gov/vuln/detail/CVE-2023-50224

Description

TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of TP-Link TL-WR841N routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the httpd service, which listens on TCP port 80 by default. The issue results from improper authentication. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. Was ZDI-CAN-19899.

Severity

CVSS 3.1 · CNA6.5 MEDIUM
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
SSVC · CISA-ADP
Exploitationactive
Automatableno
Technical impactpartial

Affected Products

VendorProductAffected versions
TP-LinkTL-WR841N
3.16.9 build 200409
V8
V9
V10
V11
V11_211209 (unaffected)
V12
V12_230317 (unaffected)
TP-LinkTL-WR841ND
V8
V9
V10
V11
V11_211209 (unaffected)
V12
V12_230317 (unaffected)
TP-LinkTL-MR6400
V1
V2
TP-LinkArcher C5
V2
TP-LinkArcher C7
V2
V2_241108 (unaffected)
V3
TP-LinkTL-WDR3600
V2
TP-LinkTL-WDR4300
V1
TP-LinkTL-WDR3500
V2
TP-LinkTL-WR740N
V4
V5
V6
V7
TP-LinkTL-WR741ND
V4
V5
V6
TP-LinkTL-WR749N
BR 6.0
BR 7.0
TP-LinkTL-MR3420
V2
V3
V4
TP-LinkTL-WR1043ND
V2
V3
V4
TP-LinkTL-WR1045ND
RU V2
TP-LinkTL-WR840N
V2
V3
TP-LinkTL-WR842N
V2
V3
V4
TP-LinkTL-WR842ND
V2
V3
V4
TP-LinkTL-WR845N
V1
V2
TP-LinkTL-WR941ND
V5
V6
V6_220610 (unaffected)
TP-LinkTL-WR945N
V1
TP-LinkTL-WA801ND
V3
V4
TP-LinkTL-WA901ND
V3
V4
V4_201030 (unaffected)
V5
V5_201030 (unaffected)

References

3 Links
Other references

Record Details

Published
2024-05-03
Last updated
2026-09-02
Assigner (CNA)
zdi
Credited to
-

Related Tool Categories

Tool categories that test for or protect against this vulnerability class.

CWE-290 · Authentication Bypass by Spoofing

CVE record data © The MITRE Corporation, used under the CVE Terms of Use. Exploited-in-the-wild data from the CISA Known Exploited Vulnerabilities catalog (CC0). Exploit prediction scores by FIRST EPSS (first.org/epss). This site is not endorsed or certified by MITRE, NVD, CISA, or FIRST.