CVE-2023-50224Active Exploitation(tp-link / archer_c1900)

HIGHCVSS 6.5 · MEDIUMCISA KEV

Exploitation ongoing with high activity in latest observed window (3 mentions)

Immediate actions

  • Patch tp-link archer_c1900 systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of TP-Link TL-WR841N routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the httpd service, which listens on TCP port 80 by default. The issue results from improper authentication. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. Was ZDI-CAN-19899.

6.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-09-24. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-290

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • archer_c1900
  • archer_c1900_firmware
  • archer_c5
  • archer_c5_firmware

Threat summary

  • Active exploitation appears in 15 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 28 mentions across 16 observed days

What's happening

  • Active exploitation reported across 15 signals
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 8 signals
  • General: 7 classified signals
  • Peaked 13d ago at 4 mentions (2026-04-09); latest day: 3
  • 28 total mentions across 16 days

Affected systems

Vendors
Products
archer_c1900archer_c1900_firmwarearcher_c5archer_c5_firmwarearcher_c7archer_c7_firmwaremr3420mr3420_firmwaremr6400mr6400_firmware

25 versions affected across 72 products

Deep dive

Activity timeline28 mentions / 16d
01234Mentions · 2026-02-27: 1Mentions · 2026-04-08: 3Mentions · 2026-04-09: 4Mentions · 2026-04-10: 4Mentions · 2026-04-11: 1Mentions · 2026-04-12: 1Mentions · 2026-04-13: 1Mentions · 2026-04-14: 3Mentions · 2026-04-17: 1Mentions · 2026-04-21: 1Mentions · 2026-04-24: 1Mentions · 2026-04-25: 1Mentions · 2026-05-22: 1Mentions · 2026-07-25: 1Mentions · 2026-10-07: 1Mentions · 2026-10-09: 3PoC Mentioned / Linked · 2026-04-17: 1Active Exploitation · 2026-02-27: 1Active Exploitation · 2026-04-08: 2Active Exploitation · 2026-04-09: 3Active Exploitation · 2026-04-10: 3Active Exploitation · 2026-04-11: 1Active Exploitation · 2026-04-12: 1Active Exploitation · 2026-04-14: 1Active Exploitation · 2026-04-17: 1Active Exploitation · 2026-05-22: 1Active Exploitation · 2026-07-25: 1Patch / Workaround · 2026-02-27: 1Patch / Workaround · 2026-04-08: 1Patch / Workaround · 2026-04-14: 2Technical Details · 2026-02-27: 1Technical Details · 2026-04-09: 2Technical Details · 2026-04-11: 1Technical Details · 2026-04-12: 1Technical Details · 2026-04-13: 1Technical Details · 2026-04-14: 1Technical Details · 2026-05-22: 102-2704-0804-0904-1004-1104-1204-1304-1404-1704-2104-2404-2505-2207-2510-0710-09
Signal classification4 categories
Active Exploitation
1458.3%
General
729.2%
Patch
28.3%
Disclosure
14.2%
Referenced assets15 URLs
Classification over time
DateTotalLabels
2026-02-271
Active Exploitation1
2026-04-083
Active Exploitation1General1Patch1
2026-04-094
Active Exploitation3General1
2026-04-104
Active Exploitation3Disclosure1
2026-04-111
Active Exploitation1
2026-04-121
Active Exploitation1
2026-04-131
General1
2026-04-143
Active Exploitation1General1Patch1
2026-04-171
Active Exploitation1
2026-04-211
General1
2026-04-241
General1
2026-04-251
General1
2026-05-221
Active Exploitation1
2026-07-251
Active Exploitation1
Full discourse20 posts
  • 摩女peace🌟🌟🌟银河系。新号,小心假号,这个是真的@peace86774949
    Active Exploitation

    TP-Link 產品的安全性在市場上評價兩極。其產品具備基本加密與NCC認證,但近年來因多項高風險資安漏洞(如 CVE-2023-50224, CVE-2025-9377)遭披露,且曾被指控遭黑客利用,導致其安全性備受爭議。 國家資通安全研究院 國家資通安全研究院 +3 關鍵安全性觀點: 安全漏洞風險: 研究發現多款舊型或特定型號 TP-Link 路由器存在「敏感資訊洩露」和「命令注入」漏洞,已被攻擊者用於建立殭屍網路。 技術與隱私防護: TP-Link 聲明其 Tapo 攝像頭使用安全可靠的 AWS 伺服器,且無「預設密碼」登錄,支援加密傳輸。 政治與背景疑慮: 美國曾因資安風險考慮封殺 TP-Link,指出其設備可能成為中國駭客攻擊工具。 建議操作: 用戶需定期更新韌體、更改預設管理員密碼、停用遠端管理功能以保障安全。 國家資通安全研究院 國家資通安全研究院 +8 總結來說,若能勤於更新韌體並妥善設定,TP-Link 設備可作為一般的家庭網路使用,但若對隱私與中國背景資安風險極度敏感,建議考慮其他品牌。

    Post summary

    The post reports that TP‑Link routers had high‑risk CVEs actively exploited by attackers to build zombie networks, and recommends firmware updates and hardening as mitigations.

    12403601.4K
    44.7K followersView on X
  • Mololuwa | Cybersecurity - (The God Complex)@cyber_rekk

    I dug into the complaints and the federal record There is actually a pretty substantial technical history behind this The biggest one is CVE-2023-50224. Russian GRU operators exploited vulnerable TP-Link routers, and the NSA/FBI say thousands of TP-Link routers were compromised. The attackers used the routers for DNS hijacking, redirecting victims' DNS requests through attacker-controlled infrastructure There are other examples too, CVE-2023-33538, a TP-Link command-injection vulnerability, was added to CISA's Known Exploited Vulnerabilities catalog because there was evidence it was being actively exploited And the Florida investigation didn't suddenly appear today. Florida's AG opened a consumer-protection investigation and subpoenaed TP-Link in December 2025, specifically asking about its security practices, software development, supply chain, corporate structure and handling of U.S. consumer data Then in April 2026, the FBI and NSA publicly said Russian military intelligence had been exploiting TP-Link routers to steal credentials and use compromised routers for DNS-hijacking operations longer post coming soon

    231104946
    23.3K followersView on X
  • Mololuwa | Cybersecurity - (The God Complex)@cyber_rekk

    Hackers found a way to turn some TP-Link routers into machines that secretly redirected people's internet traffic The attack was tied to APT28, the Russian military intelligence group One of the vulnerabilities they exploited was CVE-2023-50224 in older TP-Link routers The flaw could let an attacker retrieve sensitive information from the router, including stored credentials Once they had those credentials, they could change the router's DNS settings DNS is what helps your device turn a website name like http://gmail.com into the server address it needs to connect to The attackers replaced the router's legitimate DNS server with one they controlled And because devices connected to the router inherited those DNS settings, the compromise could extend beyond the router itself The attackers weren't necessarily trying to redirect everything The malicious DNS servers could look for requests involving specific services, particularly login pages and email services When a targeted request appeared, the DNS infrastructure could send the victim toward attacker-controlled infrastructure That gave the attackers an opportunity to steal credentials and authentication tokens The UK government said the operation was being used to carry out adversary-in-the-middle attacks And TP-Link wasn't dealing with just this one vulnerability CISA has also listed another TP-Link flaw, CVE-2023-33538, in its catalog of vulnerabilities known to have been exploited in the wild That vulnerability could allow attackers to execute commands on affected routers The more uncomfortable detail is what TP-Link now says about some of the routers affected by CVE-2023-50224 Several are old models that have reached end-of-life Some cannot receive a security patch at all So a vulnerability discovered years ago can still matter because the vulnerable router may still be sitting in someone's home or office, doing exactly what a router is supposed to do: sitting in the middle of their network and handling their traffic This is the security history sitting underneath the lawsuits filed against TP-Link this week The political claims about China are a separate question that will have to be established in court But the underlying router-security problem isn't hypothetical Security agencies have documented real exploitation of TP-Link devices by state-linked attackers

    000105918
    23.3K followersView on X
  • Inhimillinen elämä🇫🇮🇺🇦🇪🇺🇵🇸@InhimillinenE
    Patch

    Huh huh. Päivitä laitteesi. "GRU on viime vuosina hyödyntänyt erit. heikosti suojattuja kotireitittimiä osana maailmanlaajuista kybervakoiluinfrastruktuuriaan. Operaatio kohdistui GRU:n murtamiin TP-Linkin reitittimiin, joissa ei ollut korjattu CVE-2023-50224 haavoittuvuutta."

    Post summary

    A Finnish‑language warning notes that GRU exploited TP‑Link routers with the unpatched CVE‑2023‑50224, urging users to update their devices, but offers no technical or exploit details.

    01070162
    2.4K followersView on X
  • PacketSmith@PacketSmith
    General

    Netomize shares the PacketSmith Yara detection module rule and a pcap for detecting attempted exploitation of the CVE-2023-50224 vulnerability in TP-Link TL-WR841N devices. #apt28 #CVE-2023-50224 https://github.com/Netomize/RFiles/tree/main/cve_2023_50224

    Post summary

    Netomize released a Yara detection rule and pcap to identify attempts against CVE‑2023‑50224 on TP‑Link TL‑WR841N, with no exploit code, patch info, or active exploitation claims.

    02030177
    7 followersView on X
  • 横浜539@PutStickerOn
    General

    これっぽいね。 CVE-2023-50224 https://www.tp-link.com/us/support/faq/5058/

    Post summary

    The post references CVE‑2023‑50224 and a TP‑Link support link but provides no detailed information such as PoC, exploit code, active exploitation, or mitigation advice.

    01021747
    3.4K followersView on X
  • Ariolavi@AOPIRS
    General

    "Finnish authorities participated in an international operation to disrupt the cyber espionage activities of the Russian military intelligence service GRU." 👉TP-Link routers that had not been patched for a vulnerability known as CVE-2023-50224. https://www.is.fi/digitoday/tietoturva/art-2000011929820.html

    Post summary

    The post notes that TP‑Link routers remained unpatched for CVE‑2023‑50224, but offers no further technical details or evidence of exploitation.

    1102082
    526 followersView on X
  • Vlaďka Styxová@Styx_Vladimira
    Disclosure

    @AVejmelka @honzabartosek @NUKIB_CZ Aby to bylo ještě pikatnější, tak navíc na tu chybu upozornil Rus. Tedy chybu CVE-2023-50224 oznámil Aleksandar Djurdjevic (přezdívka revengsmK), který ji nahlásil přes Zero Day Initiative (ZDI-23-1808) v roce 2023. Chápeš jak je to trapné?

    Post summary

    The tweet announces the reporting of CVE‑2023‑50224 by a Russian actor via Zero Day Initiative, but provides no additional technical or exploit details.

    10110126
    1.7K followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2024-7399 2 - CVE-2023-50224 3 - CVE-2025-48700 4 - CVE-2025-20333 5 - CVE-2026-5281 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The tweet simply lists five trending CVE identifiers without providing any additional context, technical details, or evidence of exploitation.

    00011811
    1.7K followersView on X
  • Grok@grok
    Active Exploitation

    Nothing—the NSA deployed no such thing. The April 7 FBI/NSA advisory warns that Russian GRU (APT28/Fancy Bear) hackers have been exploiting vulnerable home/office routers worldwide (e.g., TP-Link via CVE-2023-50224) since at least 2024 to hijack DNS settings, steal credentials, and spy on military/government traffic. They disrupted some of these networks. Rebooting (plus firmware updates, password changes, and disabling remote access) is standard advice to clear attacker implants or changes. No backdoors involved—just basic cyber hygiene against foreign espionage.

    Post summary

    Russian GRU hackers are actively exploiting CVE-2023-50224 in TP‑Link routers to hijack DNS and steal credentials; mitigation includes rebooting, firmware updates, password changes, and disabling remote access.

    00011158
    8.7M followersView on X
  • CyberTLDR@CyberTLDR
    Active Exploitation

    APT28 exploits vulnerabilities like CVE-2023-50224 in TP-Link routers to gain remote administrative access. Attackers change the device's default DNS resolvers to actor-controlled servers. #cybersecurity #router #DNS #exploits #CVE

    Post summary

    APT28 is actively exploiting CVE‑2023‑50224 on TP‑Link routers to hijack DNS resolvers and gain remote administrative control.

    1000171
    6 followersView on X
  • Motoki KAMIMURA@usabarashi
    Active Exploitation

    https://joho-todai.com/russia-gru-hijacks-routers-steal-outlook-credentials/ > 脆弱性(CVE-2023-50224)を悪用してルーターの認証情報を取得する。次に、そのルーターのDHCP/DNS設定を書き換え、攻撃者が管理するDNSサーバーを指すように変更する。 対象機器は使っていないけど, 汎用的には, 定期的に Plan して State 差分を検出ですかね?

    Post summary

    CVE‑2023‑50224 is being actively exploited to hijack routers, steal authentication data, and redirect DNS traffic, indicating real‑world malicious use.

    00011208
    224 followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    APT28 exploited CVE-2023-50224 in SOHO routers to hijack DNS settings, redirecting traffic through attacker-controlled infrastructure. The campaign intercepted credentials from 5,000+ devices across 120 countries via adversary-in-the-middle attacks. Runtime segmentation helps contain such lateral movement from compromised network devices. #ThreatIntel 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/apt28-2025-soho-router-dns-hijacking

    Post summary

    APT28 is actively exploiting CVE-2023-50224 in SOHO routers, hijacking DNS settings and capturing credentials from over 5,000 devices across 120 countries.

    1001047
    1.9K followersView on X
  • DFIR Radar@DFIR_Radar
    Active Exploitation

    Russian 🇷🇺 APT28 (GRU Unit 26165) exploits vulnerable routers including TP-Link WR841N via CVE-2023-50224 to hijack DNS settings for adversary-in-the-middle attacks. Campaign targets email/login traffic for credential harvesting. #DFIR_Radar

    Post summary

    APT28 is actively exploiting CVE‑2023‑50224 on TP‑Link WR841N routers to hijack DNS settings and harvest credentials, with no PoC or patch discussion.

    10010199
    1.2K followersView on X
  • Tech Start XYZ@TechStartXYZ

    A pressão política é alimentada por um histórico técnico assustador: • Em 2024, a Microsoft achou 8 mil roteadores da marca formando uma rede zumbi (botnet). • Em abril de 2026, o FBI flagrou a inteligência militar russa hackeando os aparelhos (via CVE-2023-50224) para interceptar senhas e alterar o DNS das vítimas.

    1000028
    168 followersView on X
  • Kristaps Skutelis@krizdabz
    General

    @MGabalins @kursorslv Izskatās, ka šis ir par CVE-2023-50224 un tas attiecas uz TP-Link TL-WR841N ar 3.16.9 build 200409 / hardware version 12

    Post summary

    The tweet only notes that CVE-2023-50224 concerns a specific TP‑Link router model; no further details are given.

    00010142
    23.7K followersView on X
  • The Cyber Jim@thecyberjim
    Active Exploitation

    The most common router model that was exploited in the wind - TP Link WR841N using CVE-2023-50224. This vulnerability allows adversaries to steal credentials of the router via HTTP GET requests. Once the actors gained credentials of the router, a second request was sent to alter the DHCP DNS settings of the router, setting the DNS server to a malicious VPS server.

    Post summary

    The text reports that CVE-2023-50224 has been actively exploited on TP‑Link WR841N routers, allowing attackers to harvest credentials via HTTP GET and subsequently change DNS settings.

    1000078
    25 followersView on X
  • エム@PSO2:ship3@koromo_master
    Active Exploitation

    TP-Linkルーター、サポート終了なら今夜確認を 20機種がGRUに掌握されDNSを書き換えられていた /Archer C5・WR841N・CVE-2023-50224・APT28・Outlook. https://youtu.be/nSCjY_AGgF4?si=5_ZAFMDLk301jLkb

    Post summary

    The tweet alleges that 20 TP‑Link router models were hijacked by GRU with DNS manipulation, referencing CVE‑2023‑50224 and indicating active exploitation.

    00001271
    1.5K followersView on X
  • LeMagIT@LeMagIT
    Active Exploitation

    ⚠️ Votre MFA est contournée si votre routeur est vulnérable ! APT28 utilise CVE-2023-50224 pour attaques "AiTM" et voler vos tokens. Sécurisez vos équipements de bordure. #CyberResilience https://www.lemagit.fr/actualites/366641249/APT28-lexploitation-des-routeurs-SOHO-comme-levier-despionnage https://t.co/MjWdFPhVZR

    Post summary

    The post claims that APT28 is actively exploiting CVE-2023-50224 on vulnerable routers to perform AiTM attacks and steal MFA tokens, underscoring current real‑world threat activity.

    00010222
    17.9K followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc

    TRC analysis shows state-backed attackers exploited CVE-2023-50224 and CVE-2025-30237 to establish persistent router access, then used DNS manipulation for credential harvesting across 8,000+ devices. Router compromise creates upstream control points that traditional endpoint security cannot address. 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/tp-link-sued-four-more-us-states-router-security-china-ties-2026 #ThreatIntel #CloudSecurity

    0000037
    2.0K followersView on X
CPE platform detail118 entries

118 of 118 entries

PartVendorProductVersionTarget SWTarget HW
HWtp-linkarcher_c19001.0--
OStp-linkarcher_c1900_firmware---
HWtp-linkarcher_c52.0--
OStp-linkarcher_c5_firmware---
HWtp-linkarcher_c72.0--
HWtp-linkarcher_c73.0--
OStp-linkarcher_c7_firmware---
OStp-linkarcher_c7_firmware3_150508--
HWtp-linkmr34202.0--
HWtp-linkmr34203.0--
HWtp-linkmr34204.0--
OStp-linkmr3420_firmware---
HWtp-linkmr64001.0--
HWtp-linkmr64002.0--
OStp-linkmr6400_firmware---
HWtp-linktl-mr30201.0--
OStp-linktl-mr3020_firmware---
HWtp-linktl-mr32202.0--
OStp-linktl-mr3220_firmware---
HWtp-linktl-wdr36002.0--
OStp-linktl-wdr3600_firmware---
HWtp-linktl-wdr43001--
OStp-linktl-wdr4300_firmware---
HWtp-linktl-wr710n1.0--
HWtp-linktl-wr710n2.0--
OStp-linktl-wr710n_firmware---
HWtp-linktl-wr740n4.0--
HWtp-linktl-wr740n5.0--
HWtp-linktl-wr740n6.0--
HWtp-linktl-wr740n7.0--
OStp-linktl-wr740n_firmware---
HWtp-linktl-wr741nd2.0--
HWtp-linktl-wr741nd4.0--
HWtp-linktl-wr741nd5--
HWtp-linktl-wr741nd6.0--
OStp-linktl-wr741nd_firmware---
HWtp-linktl-wr743nd2.0--
OStp-linktl-wr743nd_firmware---
HWtp-linktl-wr810n1.0--
HWtp-linktl-wr810n2.0--
OStp-linktl-wr810n_firmware---
HWtp-linktl-wr840n2.0--
HWtp-linktl-wr840n3.0--
OStp-linktl-wr840n_firmware---
HWtp-linktl-wr841n10--
HWtp-linktl-wr841n11--
HWtp-linktl-wr841n12--
HWtp-linktl-wr841n8.0--
HWtp-linktl-wr841n9--
OStp-linktl-wr841n_firmware---
OStp-linktl-wr841n_firmware---
HWtp-linktl-wr841nd11.0--
OStp-linktl-wr841nd_firmware---
HWtp-linktl-wr843n2.0--
HWtp-linktl-wr843n3.0--
OStp-linktl-wr843n_firmware---
HWtp-linktl-wr902ac1--
OStp-linktl-wr902ac_firmware1_160905--
OStp-linktl-wr902ac_firmware1_170628--
HWtp-linktl-wr940n2.0--
HWtp-linktl-wr940n4.0--
HWtp-linktl-wr940n5.0--
HWtp-linktl-wr940nv3--
HWtp-linktl-wr940nv6--
OStp-linktl-wr940n_firmware---
OStp-linktl-wr940n_firmware---
HWtp-linktl-wr940n_plus6.0--
OStp-linktl-wr940n_plus_firmware6_170704--
OStp-linktl-wr940n_plus_firmware6_171115--
HWtp-linktl-wr941ndv5--
HWtp-linktl-wr941ndv6--
OStp-linktl-wr941nd_firmware---
OStp-linktl-wr941nd_firmware---
HWtp-linkwa701nd2.0--
OStp-linkwa701nd_firmware---
HWtp-linkwa801nd3.0--
HWtp-linkwa801nd4.0--
OStp-linkwa801nd_firmware---
HWtp-linkwa901nd3.0--
HWtp-linkwa901nd4.0--
HWtp-linkwa901nd5.0--
HWtp-linkwa901nd6.0--
OStp-linkwa901nd_firmware---
OStp-linkwa901nd_firmware---
OStp-linkwa901nd_firmware5_160929--
HWtp-linkwdr35002.0--
OStp-linkwdr3500_firmware---
HWtp-linkwr1043nd2.0--
HWtp-linkwr1043nd3.0--
HWtp-linkwr1043nd4.0--
OStp-linkwr1043nd_firmware---
HWtp-linkwr1045nd2.0--
OStp-linkwr1045nd_firmware---
HWtp-linkwr749n6.0--
HWtp-linkwr749n7.0--
OStp-linkwr749n_firmware---
HWtp-linkwr802n1.0--
HWtp-linkwr802n2.0--
HWtp-linkwr802n3.0--
OStp-linkwr802n_firmware---
HWtp-linkwr841hp2.0--
HWtp-linkwr841hp3.0--
OStp-linkwr841hp_firmware---
HWtp-linkwr842n2.0--
HWtp-linkwr842n3.0--
HWtp-linkwr842n4.0--
OStp-linkwr842n_firmware---
HWtp-linkwr842nd2.0--
HWtp-linkwr842nd3.0--
HWtp-linkwr842nd4.0--
OStp-linkwr842nd_firmware---
HWtp-linkwr845n1.0--
HWtp-linkwr845n2.0--
OStp-linkwr845n_firmware---
HWtp-linkwr941hp1.0--
OStp-linkwr941hp_firmware---
HWtp-linkwr945n1.0--
OStp-linkwr945n_firmware---

Explore more