---
id: CVE-2023-50224
title: >-
  TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure
  Vulnerability
summary: >-
  TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure
  Vulnerability. This vulnerability allows network-adjacent attackers to
  disclose sensitive information on affected installations of TP-Link TL-WR841N
  routers. Au…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-290
vendor: tp-link
product: tl-wr841n_firmware
affected:
  - tl-wr841n_firmware = 3.16.9
published: '2024-05-03'
updated: '2026-09-02'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2023-50224'
references:
  - url: 'https://www.tp-link.com/en/support/download/tl-wr841n/v12/#Firmware'
    label: zdi-disclosures@trendmicro.com
  - url: 'https://www.tp-link.com/us/support/faq/5058/'
    label: zdi-disclosures@trendmicro.com
  - url: 'https://www.zerodayinitiative.com/advisories/ZDI-23-1808/'
    label: zdi-disclosures@trendmicro.com
  - url: 'https://www.tp-link.com/en/support/download/tl-wr841n/v12/#Firmware'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.zerodayinitiative.com/advisories/ZDI-23-1808/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-50224
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - kev
  - in-the-wild
epss: 0.15558
epssPercentile: 0.96713
kev: true
kevDateAdded: '2025-09-03'
kevDueDate: '2025-09-24'
kevRansomware: false
exploited: true
zeroDay: true
ingestedAt: '2026-09-02T18:48:47.536Z'
---

## Overview

TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of TP-Link TL-WR841N routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the httpd service, which listens on TCP port 80 by default. The issue results from improper authentication. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. Was ZDI-CAN-19899.

## Affected

- `tl-wr841n_firmware = 3.16.9`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
