CVE-2023-50224

MEDIUMCVSS 6.5/10Actively ExploitedEPSS 17.38%

Last modified

CVE-2023-50224 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of TP-Link TL-WR841N routers. CISA has confirmed active exploitation in the wild. EPSS estimates a 17.38% chance of exploitation in the next 30 days.

Description

TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of TP-Link TL-WR841N routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the httpd service, which listens on TCP port 80 by default. The issue results from improper authentication. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. Was ZDI-CAN-19899.

Metrics

EPSS Probability
17.38%

96.9th percentile

Probability of exploitation in the next 30 days. Learn more

Exploitation Status

This vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Federal agencies must remediate by .

Weakness Enumeration

Affected Software

VendorProductVersions
Tp-LinkTl-Wr841n FirmwareAll versions
Tp-LinkTl-Wr841n Firmware>= 11_150616, < 11_211209
Tp-LinkTl-Wr841n Firmware>= 12_160624, < 12_230317
Tp-LinkMr6400 FirmwareAll versions
Tp-LinkTl-Wdr3600 FirmwareAll versions
Tp-LinkTl-Wdr4300 FirmwareAll versions
Tp-LinkWdr3500 FirmwareAll versions
Tp-LinkTl-Wr710n FirmwareAll versions
Tp-LinkTl-Wr740n FirmwareAll versions
Tp-LinkTl-Wr741nd FirmwareAll versions
Tp-LinkTl-Wr743nd FirmwareAll versions
Tp-LinkWr749n FirmwareAll versions
Tp-LinkMr3420 FirmwareAll versions
Tp-LinkWr1043nd FirmwareAll versions
Tp-LinkWr1045nd FirmwareAll versions
Tp-LinkWr802n FirmwareAll versions
Tp-LinkTl-Wr810n FirmwareAll versions
Tp-LinkTl-Wr840n FirmwareAll versions
Tp-LinkWr841hp FirmwareAll versions
Tp-LinkTl-Wr841nd FirmwareAll versions
Tp-LinkWr842n FirmwareAll versions
Tp-LinkWr842nd FirmwareAll versions
Tp-LinkTl-Wr843n FirmwareAll versions
Tp-LinkWr845n FirmwareAll versions
Tp-LinkWr945n FirmwareAll versions
Tp-LinkTl-Mr3020 FirmwareAll versions
Tp-LinkTl-Mr3220 FirmwareAll versions
Tp-LinkWa701nd FirmwareAll versions
Tp-LinkWa801nd FirmwareAll versions
Tp-LinkArcher C5 Firmware>= 2_150130, < 2_260429
Tp-LinkArcher C7 Firmware>= 2_131217, < 2_241108
Tp-LinkArcher C7 Firmware3_150508
Tp-LinkArcher C1900 Firmware< 1_260428
Tp-LinkTl-Wr902ac Firmware1_160905
Tp-LinkTl-Wr902ac Firmware1_170628
Tp-LinkTl-Wr940n FirmwareAll versions
Tp-LinkTl-Wr940n Firmware>= 5_161019, <= 5_220801
Tp-LinkTl-Wr940n Firmware>= 6_170325, < 6_250925
Tp-LinkTl-Wr940n Plus Firmware6_170704
Tp-LinkTl-Wr940n Plus Firmware6_171115
Tp-LinkWr941hp Firmware< 1_211210
Tp-LinkTl-Wr941nd FirmwareAll versions
Tp-LinkTl-Wr941nd Firmware>= 6_150206, < 6_220610
Tp-LinkWa901nd FirmwareAll versions
Tp-LinkWa901nd Firmware5_160929
Tp-LinkWa901nd Firmware>= 6_191127, < 6_220701
Tp-LinkWa901nd Firmware>= 4_151029, < 4_201030

References

Timeline

Published
Last Modified
Status
Analyzed

Frequently Asked Questions

What is CVE-2023-50224?
TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of TP-Link TL-WR841N routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the httpd service, which listens on TCP port 80 by default. The issue results from improper authentication. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. Was ZDI-CAN-19899.
How severe is CVE-2023-50224?
CVE-2023-50224 has a CVSS score of 6.5/10 (MEDIUM severity). The EPSS model estimates a 17.38% probability of exploitation in the next 30 days. This vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog.
How do I fix CVE-2023-50224?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2023

Are you affected by CVE-2023-50224?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST