Tp Link · Tp-Link Tl-Wr841N · CVE-2023-50224
**Name of the Vulnerable Software and Affected Versions**
TP-Link TL-WR841N (affected versions not specified)
**Description**
An improper authentication issue exists in the `dropbearpwd` component of the firmware, specifically within the `httpd` service that listens on TCP port 80. This flaw allows network-adjacent attackers to bypass authentication and disclose sensitive information, such as stored credentials, via HTTP GET requests. In real-world incidents, the APT28 group exploited this issue in over 18,000 devices across 120 countries to hijack DNS settings and perform adversary-in-the-middle attacks, redirecting traffic through malicious servers to intercept credentials and conduct espionage.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Update firmware to the latest available version.
Change the router administration password.
Disable remote management access.
Reboot the device to clear potential attacker implants.