EXPOSURES › CVE-2023-50224
CVE-2023-50224
HIGH ⌖ ON CISA KEV · EXPLOITEDTP-Link TL-WR841N exposed due to unpatched spoofing vulnerability, actively exploited by threat actors.
TP-Link's TL-WR841N routers, especially end-of-life models, have a spoofing vulnerability in their httpd service that allows unauthorized access to stored credentials. This is actively being exploited, posing a significant threat to networks. Users should cease using these products immediately.
Shame score — Active exploitation of a critical vulnerability in a widely used router model, indicating negligence in security updates and maintenance.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
TP-Link TL-WR841N contains an authentication bypass by spoofing vulnerability within the httpd service, which listens on TCP port 80 by default, leading to the disclose of stored credentials. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.