CVE-2023-50224: TP-Link TL-WR841N Authentication Bypass by Spoofing Vulnerability
TP-Link TL-WR841N contains an authentication bypass by spoofing vulnerability within the httpd service, which listens on TCP port 80 by default, leading to the disclose of stored credentials. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.
Other sources
TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of TP-Link TL-WR841N routers. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the httpd service, which listens on TCP port 80 by default. The issue results from improper authentication. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. . Was ZDI-CAN-19899.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
TP-Link TL-WR841Nfrom your environment.Discontinue use of the product (the material states users should discontinue product utilization due to the authentication bypass/improper authentication information disclosure).
- Compensating control
If the product cannot be mitigated per vendor instructions, discontinue product utilization (the material indicates mitigations may be unavailable for some affected/end-of-life products).
- Compensating control
Restrict network access to the router’s httpd service that listens on TCP port 80 by default, to reduce exposure to network-adjacent attackers (vulnerability is in httpd on TCP/80).
Event History
Frequently Asked Questions
What is the severity of CVE-2023-50224?
CVE-2023-50224 is a high-severity vulnerability affecting TP-Link TL-WR841N routers.
How does CVE-2023-50224 affect TP-Link TL-WR841N routers?
CVE-2023-50224 allows network-adjacent attackers to disclose sensitive information on affected TP-Link TL-WR841N installations.
What type of attackers can exploit CVE-2023-50224?
Network-adjacent attackers can exploit CVE-2023-50224 without the need for authentication.
Is there a patch for CVE-2023-50224?
Yes, users should check for firmware updates from TP-Link to mitigate CVE-2023-50224.
Which service is affected by CVE-2023-50224?
CVE-2023-50224 specifically affects the httpd service running on TCP port 80 of the TP-Link TL-WR841N routers.