Vulnerability record · CVE-2023-50224 · published 3 May 2024
CVE-2023-50224: TP-Link router httpd authentication bypass exposes stored credentials
Tp Link · Tl Wr841n Firmware
The httpd service on affected TP-Link router firmware contains an improper authentication flaw (CWE-290) that lets a network-adjacent attacker bypass authentication and read stored credentials. Because no credentials or user interaction are needed, any host on the same network segment can reach the flaw over TCP port 80. The leaked credentials can then be reused to further compromise the device or connected environment.
Description
TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of TP-Link TL-WR841N routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the httpd service, which listens on TCP port 80 by default. The issue results from improper authentication. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. Was ZDI-CAN-19899.
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
high priorityThe flaw is unauthenticated, network-adjacent, leaks credentials, and is confirmed exploited in CISA KEV, though CVSS rates it only medium severity.
What it is
The httpd service on affected TP-Link router firmware contains an improper authentication flaw (CWE-290) that lets a network-adjacent attacker bypass authentication and read stored credentials. Because no credentials or user interaction are needed, any host on the same network segment can reach the flaw over TCP port 80. The leaked credentials can then be reused to further compromise the device or connected environment.
Impact
An attacker gains disclosure of stored credentials on the router, which can be reused to log in to the device or pivot to other systems using those secrets. This is a confidentiality-only impact; no integrity or availability effect is described.
Attack surface
Reached over the network via the httpd service listening on TCP port 80 by default; the CVSS vector (AV:A/PR:N/UI:N) indicates the attacker must be on an adjacent network segment but needs no authentication and no user interaction.
Exploitation
CVE-2023-50224 is listed in CISA KEV (added 2025-09-03), confirming exploitation in the wild, and EPSS gives a 30-day probability of about 15.6 percent (96.6th percentile). No ransomware campaign use is documented.
What to do
- Apply the vendor firmware update for TL-WR841N v12 and any other affected models listed in TP-Link's advisory; patch first.
- If no firmware fix is available for a given model, discontinue use or isolate the device on a segmented network per CISA's required action.
- Restrict management access to the router's HTTP interface so only trusted administrative hosts can reach TCP port 80.
- Change any credentials stored on or reused from the affected router after patching, since they may already be exposed.
- Monitor TP-Link advisories for additional affected models and updated firmware.
Detection
- Monitor network traffic to router TCP port 80 from hosts outside the normal management subnet for requests to credential-handling endpoints.
- Review router and upstream firewall logs for unexpected or unauthenticated HTTP access to the device's web interface.
- Alert on authentication events or configuration changes on the router that originate from unusual source addresses.
- Track CISA KEV status and scan the network for affected TP-Link models still running unpatched firmware.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2023-50224 to the Known Exploited Vulnerabilities catalog on 3 September 2025 as "TP-Link TL-WR841N Authentication Bypass by Spoofing Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 24 September 2025.
Affected products
36 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.tp-link.com/en/support/download/tl-wr841n/v12/#Firmware | Product |
| https://www.tp-link.com/us/support/faq/5058/ | Vendor Advisory |
| https://www.zerodayinitiative.com/advisories/ZDI-23-1808/ | Third Party Advisory |
| https://www.tp-link.com/en/support/download/tl-wr841n/v12/#Firmware | Product |
| https://www.zerodayinitiative.com/advisories/ZDI-23-1808/ | Third Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-50224 | US Government Resource |
Track CVE-2023-50224 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-50224), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.