CVE-2023-50224
unknown
KEV
CVSS v3
—
CVSS v2
—
VIR risk
1.5
Description
TP-Link TL-WR841N contains an authentication bypass by spoofing vulnerability within the httpd service, which listens on TCP port 80 by default, leading to the disclose of stored credentials. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.
CISA KEV
- Vendor
- TP-Link
- Product
- TL-WR841N
- Due date
- 2025-09-24
Predictions
Exploit likelihood
99%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: cisa-kev — https://www.tp-link.com/us/support/faq/4308/ ; https://nvd.nist.gov/vuln/detail/CVE-2023-50224
Exploits
References
Verify integrity in audit chain (admin only). AS-IS.