← Vulnerability feed

Vulnerability record · CVE-2023-50224 · published 3 May 2024

CVE-2023-50224: TP-Link router httpd authentication bypass exposes stored credentials

Tp Link · Tl Wr841n Firmware

The httpd service on affected TP-Link router firmware contains an improper authentication flaw (CWE-290) that lets a network-adjacent attacker bypass authentication and read stored credentials. Because no credentials or user interaction are needed, any host on the same network segment can reach the flaw over TCP port 80. The leaked credentials can then be reused to further compromise the device or connected environment.

6.5 CVSS 3.1 Medium CISA KEV since 3 Sep 2025 EPSS 16% · top 3.3% CWE-290 · Authentication bypass by spoofing
6.5CVSS 3.1 base score
16%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
36Affected product versions listed by NVD
6References
3 Sep 2026Last modified by NVD

Description

TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of TP-Link TL-WR841N routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the httpd service, which listens on TCP port 80 by default. The issue results from improper authentication. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. Was ZDI-CAN-19899.

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityThe flaw is unauthenticated, network-adjacent, leaks credentials, and is confirmed exploited in CISA KEV, though CVSS rates it only medium severity.

What it is

The httpd service on affected TP-Link router firmware contains an improper authentication flaw (CWE-290) that lets a network-adjacent attacker bypass authentication and read stored credentials. Because no credentials or user interaction are needed, any host on the same network segment can reach the flaw over TCP port 80. The leaked credentials can then be reused to further compromise the device or connected environment.

Impact

An attacker gains disclosure of stored credentials on the router, which can be reused to log in to the device or pivot to other systems using those secrets. This is a confidentiality-only impact; no integrity or availability effect is described.

Attack surface

Reached over the network via the httpd service listening on TCP port 80 by default; the CVSS vector (AV:A/PR:N/UI:N) indicates the attacker must be on an adjacent network segment but needs no authentication and no user interaction.

Exploitation

CVE-2023-50224 is listed in CISA KEV (added 2025-09-03), confirming exploitation in the wild, and EPSS gives a 30-day probability of about 15.6 percent (96.6th percentile). No ransomware campaign use is documented.

What to do

  • Apply the vendor firmware update for TL-WR841N v12 and any other affected models listed in TP-Link's advisory; patch first.
  • If no firmware fix is available for a given model, discontinue use or isolate the device on a segmented network per CISA's required action.
  • Restrict management access to the router's HTTP interface so only trusted administrative hosts can reach TCP port 80.
  • Change any credentials stored on or reused from the affected router after patching, since they may already be exposed.
  • Monitor TP-Link advisories for additional affected models and updated firmware.

Detection

  • Monitor network traffic to router TCP port 80 from hosts outside the normal management subnet for requests to credential-handling endpoints.
  • Review router and upstream firewall logs for unexpected or unauthenticated HTTP access to the device's web interface.
  • Alert on authentication events or configuration changes on the router that originate from unusual source addresses.
  • Track CISA KEV status and scan the network for affected TP-Link models still running unpatched firmware.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2023-50224 to the Known Exploited Vulnerabilities catalog on 3 September 2025 as "TP-Link TL-WR841N Authentication Bypass by Spoofing Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 24 September 2025.

Affected products

36 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-50224 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.6CVE-2025-9377TP-Link Archer C7 and TL-WR841N Parental Control OS Command InjectionAn OS command injection flaw (CWE-78) exists in the Parental Control page of TP-Link Archer C7(EU) V2 and TL-WR841N/ND(MS) V9 routers, allowing an au…KEVEPSS 34%analysed7.5CVE-2015-3035TP-Link router directory traversal allows unauthenticated file readA path traversal flaw in the web interface of multiple TP-Link Archer and TL-WR/WDR router models lets a remote attacker read arbitrary files by plac…KEVEPSS 84%analysed9.8CVE-2022-4498Tp-link archer c5 firmware out-of-bounds write vulnerabilityIn TP-Link routers, Archer C5 and WR710N-V1, running the latest available code, when receiving HTTP Basic Authentication the httpd service can be sen…EPSS 1.8%9.8CVE-2020-35575Tp-link wa901nd firmware vulnerabilityA password-disclosure issue in the web interface on certain TP-Link devices allows a remote attacker to get full administrative access to the web pan…EPSS 7.6%8.0CVE-2023-39224Tp-link archer c7 firmware os command injection vulnerabilityArcher C5 firmware all versions and Archer C7 firmware versions prior to 'Archer C7(JP)_V2_230602' allow a network-adjacent authenticated attacker to…EPSS 0.40%7.5CVE-2022-4499Tp-link archer c5 firmware observable discrepancy vulnerabilityTP-Link routers, Archer C5 and WR710N-V1, using the latest software, the strcmp function used for checking credentials in httpd, is susceptible to a …EPSS 0.71%7.2CVE-2018-19537Tp-link archer c5 firmware unrestricted file upload vulnerabilityTP-Link Archer C5 devices through V2_160201_US allow remote command execution via shell metacharacters on the wan_dyn_hostname line of a configuratio…EPSS 6.0%5.4CVE-2026-5363Tp-link archer c7 firmware inadequate encryption strength vulnerabilityInadequate Encryption Strength vulnerability in TP-Link Archer C7 v5 and v5.8 (uhttpd modules) allows Password Recovery Exploitation. The web interfa…EPSS 0.11%

Source: NIST National Vulnerability Database (record CVE-2023-50224), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.