SecBoard
Zurück zur CVE-Übersicht

CVE-2023-50224

MEDIUM(6.5)KEV — Aktiv ausgenutzt

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Risk Signal Score51/100 — HOCH
  • CVSS 6.5 — Mittel
  • Im CISA KEV-Katalog (aktiv ausgenutzt)

CISA KEV

Bestätigt ausgenutzt

EPSS-Score

15.6%

Exploit-Wahrscheinlichkeit (30 Tage)

CVSS Score

6.5

Technische Schwere

SecBoard-Einordnung

CVE-2023-50224 betrifft die Firmware des TP-Link TL-WR841N Routers und stellt eine Schwachstelle zur Offenlegung sensibler Informationen dar. Die Schwachstelle liegt im httpd-Dienst, der standardmäßig auf TCP-Port 80 lauscht, und resultiert aus einer fehlerhaften Authentifizierung. Angreifer können diese Schwachstelle ohne Authentifizierung ausnutzen, um gespeicherte Anmeldeinformationen offenzulegen.

KI-gestützte Einordnung auf Basis der NVD-Daten.

Beschreibung

TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of TP-Link TL-WR841N routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the httpd service, which listens on TCP port 80 by default. The issue results from improper authentication. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. Was ZDI-CAN-19899.

Betroffene Produkte

  • cpe:2.3:o:tp-link:tl-wr841n_firmware:-:*:*:*:*:*:*:*
  • cpe:2.3:o:tp-link:tl-wr841n_firmware:*:*:*:*:*:*:*:*
  • cpe:2.3:o:tp-link:tl-wr841n_firmware:*:*:*:*:*:*:*:*
  • cpe:2.3:o:tp-link:mr6400_firmware:-:*:*:*:*:*:*:*
  • cpe:2.3:o:tp-link:tl-wdr3600_firmware:-:*:*:*:*:*:*:*
  • cpe:2.3:o:tp-link:tl-wdr4300_firmware:-:*:*:*:*:*:*:*
  • cpe:2.3:o:tp-link:wdr3500_firmware:-:*:*:*:*:*:*:*
  • cpe:2.3:o:tp-link:tl-wr710n_firmware:-:*:*:*:*:*:*:*
  • cpe:2.3:o:tp-link:tl-wr740n_firmware:-:*:*:*:*:*:*:*
  • cpe:2.3:o:tp-link:tl-wr741nd_firmware:-:*:*:*:*:*:*:*
  • cpe:2.3:o:tp-link:tl-wr743nd_firmware:-:*:*:*:*:*:*:*
  • cpe:2.3:o:tp-link:wr749n_firmware:-:*:*:*:*:*:*:*
  • cpe:2.3:o:tp-link:mr3420_firmware:-:*:*:*:*:*:*:*
  • cpe:2.3:o:tp-link:wr1043nd_firmware:-:*:*:*:*:*:*:*
  • cpe:2.3:o:tp-link:wr1045nd_firmware:-:*:*:*:*:*:*:*
  • cpe:2.3:o:tp-link:wr802n_firmware:-:*:*:*:*:*:*:*
  • cpe:2.3:o:tp-link:tl-wr810n_firmware:-:*:*:*:*:*:*:*
  • cpe:2.3:o:tp-link:tl-wr840n_firmware:-:*:*:*:*:*:*:*
  • cpe:2.3:o:tp-link:wr841hp_firmware:-:*:*:*:*:*:*:*
  • cpe:2.3:o:tp-link:tl-wr841nd_firmware:-:*:*:*:*:*:*:*

Referenzen