← All CVEs

CVE-2023-50224

medium · 6.5Actively exploited

On the CISA Known Exploited Vulnerabilities catalog

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Added 2025-09-03Remediation due 2025-09-24

TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of TP-Link TL-WR841N routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the httpd service, which listens on TCP port 80 by default. The issue results from improper authentication. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. Was ZDI-CAN-19899.

6.5
CVSS
15.6%
EPSS (exploit prob.)
97th
EPSS percentile
2024-05-03
Published

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Weaknesses

CWE-290

Affected products

VendorProductAffected versions
tp-linktl-wr841n_firmwareall versions
tp-linktl-wr841n8.0
tp-linktl-wr841n9
tp-linktl-wr841n10
tp-linktl-wr841n_firmware>= 11_150616, < 11_211209
tp-linktl-wr841n11
tp-linktl-wr841n_firmware>= 12_160624, < 12_230317
tp-linktl-wr841n12
tp-linkmr6400_firmwareall versions
tp-linkmr64001.0
tp-linkmr64002.0
tp-linktl-wdr3600_firmwareall versions
tp-linktl-wdr36002.0
tp-linktl-wdr4300_firmwareall versions
tp-linktl-wdr43001
tp-linkwdr3500_firmwareall versions
tp-linkwdr35002.0
tp-linktl-wr710n_firmwareall versions
tp-linktl-wr710n1.0
tp-linktl-wr710n2.0
tp-linktl-wr740n_firmwareall versions
tp-linktl-wr740n4.0
tp-linktl-wr740n5.0
tp-linktl-wr740n6.0
tp-linktl-wr740n7.0
tp-linktl-wr741nd_firmwareall versions
tp-linktl-wr741nd2.0
tp-linktl-wr741nd4.0
tp-linktl-wr741nd5
tp-linktl-wr741nd6.0
tp-linktl-wr743nd_firmwareall versions
tp-linktl-wr743nd2.0
tp-linkwr749n_firmwareall versions
tp-linkwr749n6.0
tp-linkwr749n7.0
tp-linkmr3420_firmwareall versions
tp-linkmr34202.0
tp-linkmr34203.0
tp-linkmr34204.0
tp-linkwr1043nd_firmwareall versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2023-50224