CVE-2023-50224: TP-Link TL-WR841N Authentication Bypass by Spoofing Vulnerability
This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of TP-Link TL-WR841N routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the httpd service, which listens on TCP port 80 by default. The issue results from improper authentication. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise.
Other sources
TP-Link TL-WR841N contains an authentication bypass by spoofing vulnerability within the httpd service, which listens on TCP port 80 by default, leading to the disclose of stored credentials. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
TP-Link TL-WR841Nfrom your environment.Discontinue use and remove/uninstall the affected TL-WR841N product from your environment.
- Compensating control
Discontinue product utilization of TP-Link TL-WR841N routers described as impacted (EoL/EoS).
- Compensating control
Since the flaw is in the httpd service listening on TCP port 80, restrict/limit network access to TCP port 80 on affected TP-Link TL-WR841N devices so network-adjacent attackers cannot reach it.
- Compensating control
Mitigate per vendor instructions for TP-Link TL-WR841N authentication bypass/improper authentication information disclosure (ZDI-CAN-19899) if mitigations are available; otherwise discontinue product utilization.
Event History
Frequently Asked Questions
What is the severity of CVE-2023-50224?
CVE-2023-50224 is a high-severity vulnerability affecting TP-Link TL-WR841N routers.
How does CVE-2023-50224 affect TP-Link TL-WR841N routers?
CVE-2023-50224 allows network-adjacent attackers to disclose sensitive information on affected TP-Link TL-WR841N installations.
What type of attackers can exploit CVE-2023-50224?
Network-adjacent attackers can exploit CVE-2023-50224 without the need for authentication.
Is there a patch for CVE-2023-50224?
Yes, users should check for firmware updates from TP-Link to mitigate CVE-2023-50224.
Which service is affected by CVE-2023-50224?
CVE-2023-50224 specifically affects the httpd service running on TCP port 80 of the TP-Link TL-WR841N routers.