Junglewise Threat Intelligence

CVE-2023-50224: TP-Link TL-WR841N authentication bypass in httpd service

CVE-2023-50224 · Severity: critical · CVSS 6.5 · Exploited in the wild · Published 2025-09-03

Technologies: TP-Link TL-WR841N. Vendors: TP-Link.

Executive brief

The TP-Link TL-WR841N is a wireless router used for home and small office networking. A security flaw allows an attacker on the same local network to bypass security checks and steal stored login credentials. This could lead to a full takeover of the device and the network it manages. Because this product may be at its end-of-life, users are advised to replace the hardware if updates are unavailable.

Technical details

An improper authentication vulnerability (CWE-290) exists in the 'dropbearpwd' component of the httpd service on TP-Link TL-WR841N routers. The service, which listens on TCP port 80, fails to correctly validate authentication requests, allowing a network-adjacent attacker to bypass security controls without valid credentials. Successful exploitation enables the attacker to disclose sensitive information, specifically stored credentials, which can be used for further administrative compromise of the device. This vulnerability has been observed in active exploitation according to CISA.

Affected products

  • TP-Link TL-WR841N v12 (Firmware 3.16.9 Build 200409)

Timeline

  • 2024-05-02: disclosed: Initial report by Zero Day Initiative
  • 2025-09-03: kev added: Added to CISA Known Exploited Vulnerabilities catalog

Related threats