CVE-2023-50224: TP-Link TL-WR841N Authentication Bypass by Spoofing Vulnerability

Published Dec 19, 2023
·
Updated

This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of TP-Link TL-WR841N routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the httpd service, which listens on TCP port 80 by default. The issue results from improper authentication. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise.

Other sources

TP-Link TL-WR841N contains an authentication bypass by spoofing vulnerability within the httpd service, which listens on TCP port 80 by default, leading to the disclose of stored credentials. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

CISA

Affected Software

125 affected components
TP-Link TL-WR841N
All of the following
TP-Link TL-WR841N firmware
Any of the following
TP-Link TL-WR841N=8.0
TP-Link TL-WR841N=9
TP-Link TL-WR841N=10
All of the following
TP-Link TL-WR841N firmware>=11_150616<11_211209
TP-Link TL-WR841N=11
All of the following
TP-Link TL-WR841N firmware>=12_160624<12_230317
TP-Link TL-WR841N=12
All of the following
TP-Link Mr6400 Firmware
Any of the following
TP-Link MR6400=1.0
TP-Link MR6400=2.0
All of the following
TP-Link Tl-wdr3600 Firmware
TP-Link TL-WDR3600=2.0
All of the following
TP-Link Tl-wdr4300 Firmware
TP-Link TL-WDR4300=1
All of the following
TP-Link Wdr3500 Firmware
TP-Link WDR3500=2.0
All of the following
TP-Link Tl-wr710n Firmware
Any of the following
TP-Link Tl-wr710n=1.0
TP-Link Tl-wr710n=2.0
All of the following
TP-Link Tl-wr740n Firmware
Any of the following
TP-Link TL-WR740N=4.0
TP-Link TL-WR740N=5.0
TP-Link TL-WR740N=6.0
TP-Link TL-WR740N=7.0
All of the following
TP-Link Tl-wr741nd Firmware
Any of the following
TP-Link TL-WR741ND=2.0
TP-Link TL-WR741ND=4.0
TP-Link TL-WR741ND=5
TP-Link TL-WR741ND=6.0
All of the following
TP-Link Tl-wr743nd Firmware
TP-Link TL-WR743ND=2.0
All of the following
TP-Link Wr749n Firmware
Any of the following
TP-Link WR749N=6.0
TP-Link WR749N=7.0
All of the following
TP-Link Mr3420 Firmware
Any of the following
TP-Link MR3420=2.0
TP-Link MR3420=3.0
TP-Link MR3420=4.0
All of the following
TP-Link Wr1043nd Firmware
Any of the following
TP-Link WR1043ND=2.0
TP-Link WR1043ND=3.0
TP-Link WR1043ND=4.0
All of the following
TP-Link Wr1045nd Firmware
TP-Link WR1045ND=2.0
All of the following
TP-Link Wr802n Firmware
Any of the following
TP-Link WR802N=1.0
TP-Link WR802N=2.0
TP-Link WR802N=3.0
All of the following
TP-Link Tl-wr810n Firmware
Any of the following
TP-Link Tl-wr810n=1.0
TP-Link Tl-wr810n=2.0
All of the following
TP-Link Tl-wr840n Firmware
Any of the following
TP-Link TL-WR840N=2.0
TP-Link TL-WR840N=3.0
All of the following
TP-Link Wr841hp Firmware
Any of the following
TP-Link WR841HP=2.0
TP-Link WR841HP=3.0
All of the following
TP-Link Tl-wr841nd Firmware
TP-Link TL-WR841ND=11.0
All of the following
TP-Link Wr842n Firmware
Any of the following
TP-Link WR842N=2.0
TP-Link WR842N=3.0
TP-Link WR842N=4.0
All of the following
TP-Link Wr842nd Firmware
Any of the following
TP-Link WR842ND=2.0
TP-Link WR842ND=3.0
TP-Link WR842ND=4.0
All of the following
TP-Link Tl-wr843n Firmware
Any of the following
TP-Link Tl-wr843n=2.0
TP-Link Tl-wr843n=3.0
All of the following
TP-Link Wr845n Firmware
Any of the following
TP-Link WR845N=1.0
TP-Link WR845N=2.0
All of the following
TP-Link Wr945n Firmware
TP-Link WR945N=1.0
All of the following
TP-Link Tl-mr3020 Firmware
TP-Link Tl-mr3020=1.0
All of the following
TP-Link Tl-mr3220 Firmware
TP-Link TL-MR3220=2.0
All of the following
TP-Link Mr3420 Firmware
Any of the following
TP-Link MR3420=2.0
TP-Link MR3420=3.0
All of the following
TP-Link Wa701nd Firmware
TP-Link WA701ND=2.0
All of the following
TP-Link Wa801nd Firmware
Any of the following
TP-Link WA801ND=3.0
TP-Link WA801ND=4.0
All of the following
TP-Link Archer C5 Firmware>=2_150130<2_260429
TP-Link Archer C5=2.0
All of the following
TP-Link Archer C7 Firmware>=2_131217<2_241108
TP-Link Archer C7=2.0
All of the following
TP-Link Archer C7 Firmware=3_150508
TP-Link Archer C7=3.0
All of the following
TP-Link Archer C1900 Firmware<1_260428
TP-Link Archer C1900=1.0
All of the following
Any of the following
TP-Link TL-WR902AC firmware=1_160905
TP-Link TL-WR902AC firmware=1_170628
TP-Link TL-WR902AC=1
All of the following
TP-Link Tl-wr940n Firmware
Any of the following
TP-Link TL-WR940N=2.0
TP-Link TL-WR940N=4.0
TP-Link TL-WR940N=v3
All of the following
TP-Link Tl-wr940n Firmware>=5_161019<=5_220801
TP-Link TL-WR940N=5.0
All of the following
TP-Link Tl-wr940n Firmware>=6_170325<6_250925
TP-Link TL-WR940N=v6
All of the following
Any of the following
TP-Link Tl-wr940n Plus Firmware=6_170704
TP-Link Tl-wr940n Plus Firmware=6_171115
TP-Link Tl-wr940n Plus=6.0
All of the following
TP-Link Wr941hp Firmware<1_211210
TP-Link WR941HP=1.0
All of the following
TP-Link Tl-wr941nd Firmware
TP-Link TL-WR941ND=v5
All of the following
TP-Link Tl-wr941nd Firmware>=6_150206<6_220610
TP-Link TL-WR941ND=v6
All of the following
TP-Link Wa901nd Firmware
TP-Link WA901ND=3.0
All of the following
TP-Link Wa901nd Firmware=5_160929
TP-Link WA901ND=5.0
All of the following
TP-Link Wa901nd Firmware>=6_191127<6_220701
TP-Link WA901ND=6.0
All of the following
TP-Link Wa901nd Firmware>=4_151029<4_201030
TP-Link WA901ND=4.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Remove

    Remove TP-Link TL-WR841N from your environment.

    Discontinue use and remove/uninstall the affected TL-WR841N product from your environment.

  2. Compensating control

    Discontinue product utilization of TP-Link TL-WR841N routers described as impacted (EoL/EoS).

  3. Compensating control

    Since the flaw is in the httpd service listening on TCP port 80, restrict/limit network access to TCP port 80 on affected TP-Link TL-WR841N devices so network-adjacent attackers cannot reach it.

  4. Compensating control

    Mitigate per vendor instructions for TP-Link TL-WR841N authentication bypass/improper authentication information disclosure (ZDI-CAN-19899) if mitigations are available; otherwise discontinue product utilization.

Event History

Dec 4, 2023
News Published
06:01 AM
Dec 18, 2023
News Published
02:25 AM
Dec 19, 2023
Advisory Published
via ZDI·12:00 AM
Data Sourced
via ZDI·12:00 AM
DescriptionSeverityAffected Software
Jan 15, 2024
News Published
03:34 PM
Apr 29, 2024
News Published
02:29 AM
May 3, 2024
CVE Published
via MITRE·02:14 AM
Data Sourced
via MITRE·02:14 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:16 AM
DescriptionSeverityWeaknessAffected Software
May 6, 2024
News Published
02:30 AM
May 13, 2024
News Published
02:21 AM
Jun 3, 2024
News Published
12:02 PM
Jul 1, 2024
News Published
03:35 AM
Jul 22, 2024
News Published
03:44 AM
Sep 30, 2024
News Published
03:02 AM
Nov 11, 2024
News Published
03:28 AM
Feb 10, 2025
News Published
02:30 AM
Mar 3, 2025
News Published
03:31 AM
Mar 10, 2025
News Published
01:56 AM
Jul 13, 2025
News Published
11:46 PM
Jul 21, 2025
News Published
12:13 AM
Jul 28, 2025
News Published
12:29 AM
Aug 4, 2025
News Published
12:01 AM
Aug 10, 2025
News Published
10:39 PM
Aug 25, 2025
News Published
12:57 AM
Sep 1, 2025
News Published
01:13 AM
Sep 3, 2025
Known Exploited
via CISA·12:00 AM
Data Sourced
via CISA·12:00 AM
RemedyDescriptionAffected Software
Sep 4, 2025
News Published
via BleepingComputer·04:21 PM
News Published
via BleepingComputer·04:22 PM
Sep 8, 2025
News Published
via The Register·11:46 AM
News Published
via The Register·11:49 AM
Mar 25, 2026
News Published
via BleepingComputer·11:11 AM

Frequently Asked Questions

1

What is the severity of CVE-2023-50224?

CVE-2023-50224 is a high-severity vulnerability affecting TP-Link TL-WR841N routers.

2

How does CVE-2023-50224 affect TP-Link TL-WR841N routers?

CVE-2023-50224 allows network-adjacent attackers to disclose sensitive information on affected TP-Link TL-WR841N installations.

3

What type of attackers can exploit CVE-2023-50224?

Network-adjacent attackers can exploit CVE-2023-50224 without the need for authentication.

4

Is there a patch for CVE-2023-50224?

Yes, users should check for firmware updates from TP-Link to mitigate CVE-2023-50224.

5

Which service is affected by CVE-2023-50224?

CVE-2023-50224 specifically affects the httpd service running on TCP port 80 of the TP-Link TL-WR841N routers.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203