Skip to content
COOEY

EXPOSURES › CVE-2023-50224

CVE-2023-50224

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2025-09-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2023-50224 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 90/100 exploited-in-wildunpatched

TP-Link TL-WR841N exposed due to unpatched spoofing vulnerability, actively exploited by threat actors.

TP-Link's TL-WR841N routers, especially end-of-life models, have a spoofing vulnerability in their httpd service that allows unauthorized access to stored credentials. This is actively being exploited, posing a significant threat to networks. Users should cease using these products immediately.

Shame score — Active exploitation of a critical vulnerability in a widely used router model, indicating negligence in security updates and maintenance.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

TP-Link TL-WR841N contains an authentication bypass by spoofing vulnerability within the httpd service, which listens on TCP port 80 by default, leading to the disclose of stored credentials. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.