Tp-link
Tp-link Tl-wr841n Firmware: vulnerabilidades y CVE
Tp-link Tl-wr841n Firmware tiene 39 vulnerabilidades publicadas, 5 de ellas en los últimos 12 meses. 4 son críticas y 4 figuran en el catálogo de explotación activa de CISA.
CVE39
Últimos 12 meses5
Críticas4
Explotadas activamente4
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-50224 | Media (6.5) | 16% | ⚠ Explotación activa | 3 may 2024 | TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of TP-Link… |
| CVE-2025-9377 | Alta (8.6) | 34% | ⚠ Explotación activa | 29 ago 2025 | The authenticated remote command execution (RCE) vulnerability exists in the Parental Control page on TP-Link Archer C7(EU) V2 and TL-WR841N/ND(MS) V9. This issue affects Archer C7(EU) V2: before 241108 and… |
| CVE-2023-33538 | Alta (8.8) | 42% | ⚠ Explotación activa | 7 jun 2023 | TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 was discovered to contain a command injection vulnerability via the component /userRpm/WlanNetworkRpm . |
| CVE-2015-3035 | Alta (7.5) | 84% | ⚠ Explotación activa | 22 abr 2015 | Directory traversal vulnerability in TP-LINK Archer C5 (1.2) with firmware before 150317, C7 (2.0) with firmware before 150304, and C8 (1.0) with firmware before 150316, Archer C9 (1.0), TL-WDR3500 (1.0), TL-WDR3600… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-9105 | Media (6.8) | 1.1% | — | 29 jun 2026 | An authenticated stack-based buffer overflow vulnerability exists in the web management interface of TP-Link TL-WR841N v14. A remote authenticated attacker can send crafted HTTP requests to cause the embedded web server… |
| CVE-2026-5039 | Media (6.1) | 0.21% | — | 23 abr 2026 | TP-Link TL-WR841N v13 uses DES-CBC encryption in the TDDPv2 debug protocol with a cryptographic key derived from default web management credentials, making the key predictable if device is left in default configuration.… |
| CVE-2026-3622 | Alta (7.1) | 0.70% | — | 26 mar 2026 | The vulnerability exists in the UPnP component of TL-WR841N v14, where improper input validation leads to an out-of-bounds read, potentially causing a crash of the UPnP service. Successful exploitation can cause the… |
| CVE-2026-3227 | Alta (8.5) | 1.8% | — | 16 mar 2026 | A command injection vulnerability was identified in TP-Link TL-WR802N v4, TL-WR841N v14, and TL-WR840N v6 due to improper neutralization of special elements used in an OS command. In the router configuration import… |
| CVE-2025-9014 | Media (6.3) | 0.50% | — | 15 ene 2026 | A Null Pointer Dereference vulnerability exists in the referer header check of the web portal of TP-Link TL-WR841N v14, caused by improper input validation. A remote, unauthenticated attacker can exploit this flaw and… |
| CVE-2025-9377 | Alta (8.6) | 34% | ⚠ Explotación activa | 29 ago 2025 | The authenticated remote command execution (RCE) vulnerability exists in the Parental Control page on TP-Link Archer C7(EU) V2 and TL-WR841N/ND(MS) V9. This issue affects Archer C7(EU) V2: before 241108 and… |
| CVE-2025-53715 | Media (6.9) | 0.31% | — | 29 jul 2025 | A vulnerability has been found in TP-Link TL-WR841N V11. The vulnerability exists in the /userRpm/Wan6to4TunnelCfgRpm.htm file due to missing input parameter validation, which may lead to the buffer overflow to cause a… |
| CVE-2025-53714 | Media (6.9) | 0.31% | — | 29 jul 2025 | A vulnerability has been found in TP-Link TL-WR841N V11. The vulnerability exists in the /userRpm/WzdWlanSiteSurveyRpm_AP.htm file due to missing input parameter validation, which may lead to the buffer overflow to… |
| CVE-2025-53713 | Media (6.9) | 0.31% | — | 29 jul 2025 | A vulnerability has been found in TP-Link TL-WR841N V11. The vulnerability exists in the /userRpm/WlanNetworkRpm_APC.htm file due to missing input parameter validation, which may lead to the buffer overflow to cause a… |
| CVE-2025-53712 | Media (6.9) | 0.31% | — | 29 jul 2025 | A vulnerability has been found in TP-Link TL-WR841N V11. The vulnerability exists in the /userRpm/WlanNetworkRpm_AP.htm file due to missing input parameter validation, which may lead to the buffer overflow to cause a… |
| CVE-2025-53711 | Media (6.9) | 0.31% | — | 29 jul 2025 | A vulnerability has been found in TP-Link TL-WR841N v11, TL-WR842ND v2 and TL-WR494N v3. The vulnerability exists in the /userRpm/WlanNetworkRpm.htm file due to missing input parameter validation, which may lead to the… |
| CVE-2023-50224 | Media (6.5) | 16% | ⚠ Explotación activa | 3 may 2024 | TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of TP-Link… |
| CVE-2023-39471 | Alta (8.8) | 0.91% | — | 3 may 2024 | TP-Link TL-WR841N ated_tp Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link TL-WR841N routers.… |
| CVE-2023-36489 | Alta (8.8) | 0.56% | — | 6 sept 2023 | Multiple TP-LINK products allow a network-adjacent unauthenticated attacker to execute arbitrary OS commands. Affected products/versions are as follows: TL-WR802N firmware versions prior to 'TL-WR802N(JP)_V4_221008',… |
| CVE-2023-36359 | Alta (7.5) | 0.81% | — | 22 jun 2023 | TP-Link TL-WR940N V4, TL-WR841N V8/V10, TL-WR940N V2/V3 and TL-WR941ND V5/V6 were discovered to contain a buffer overflow in the component /userRpm/QoSRuleListRpm. This vulnerability allows attackers to cause a Denial… |
| CVE-2023-36358 | Alta (7.7) | 0.70% | — | 22 jun 2023 | TP-Link TL-WR940N V2/V3/V4, TL-WR941ND V5/V6, TL-WR743ND V1 and TL-WR841N V8 were discovered to contain a buffer overflow in the component /userRpm/AccessCtrlAccessTargetsRpm. This vulnerability allows attackers to… |
| CVE-2023-36357 | Alta (7.7) | 0.80% | — | 22 jun 2023 | An issue in the /userRpm/LocalManageControlRpm component of TP-Link TL-WR940N V2/V4/V6, TL-WR841N V8/V10, and TL-WR941ND V5 allows attackers to cause a Denial of Service (DoS) via a crafted GET request. |
| CVE-2023-36356 | Alta (7.7) | 0.71% | — | 22 jun 2023 | TP-Link TL-WR940N V2/V4/V6, TL-WR841N V8, TL-WR941ND V5, and TL-WR740N V1/V2 were discovered to contain a buffer read out-of-bounds via the component /userRpm/VirtualServerRpm. This vulnerability allows attackers to… |
| CVE-2023-36354 | Alta (7.5) | 0.81% | — | 22 jun 2023 | TP-Link TL-WR940N V4, TL-WR841N V8/V10, TL-WR740N V1/V2, TL-WR940N V2/V3, and TL-WR941ND V5/V6 were discovered to contain a buffer overflow in the component /userRpm/AccessCtrlTimeSchedRpm. This vulnerability allows… |
| CVE-2023-33538 | Alta (8.8) | 42% | ⚠ Explotación activa | 7 jun 2023 | TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 was discovered to contain a command injection vulnerability via the component /userRpm/WlanNetworkRpm . |
| CVE-2023-33537 | Alta (8.1) | 0.90% | — | 7 jun 2023 | TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 was discovered to contain a buffer overflow via the component /userRpm/FixMapCfgRpm. |
| CVE-2023-33536 | Alta (8.1) | 0.90% | — | 7 jun 2023 | TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 was discovered to contain a buffer overflow via the component /userRpm/WlanMacFilterRpm. |
| CVE-2022-46912 | Alta (8.8) | 1.0% | — | 20 dic 2022 | An issue in the firmware update process of TP-Link TL-WR841N / TL-WA841ND V7 3.13.9 and earlier allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via uploading a crafted firmware image. |
| CVE-2022-42202 | Media (6.1) | 0.47% | — | 18 oct 2022 | TP-Link TL-WR841N 8.0 4.17.16 Build 120201 Rel.54750n is vulnerable to Cross Site Scripting (XSS). |
| CVE-2022-30024 | Alta (8.8) | 2.0% | — | 14 jul 2022 | A buffer overflow in the httpd daemon on TP-Link TL-WR841N V12 (firmware version 3.16.9) devices allows an authenticated remote attacker to execute arbitrary code via a GET request to the page for the System Tools of… |
| CVE-2022-25073 | Crítica (9.8) | 13% | — | 24 feb 2022 | TL-WR841Nv14_US_0.9.1_4.18 routers were discovered to contain a stack overflow in the function dm_fillObjByStr(). This vulnerability allows unauthenticated attackers to execute arbitrary code. |
| CVE-2022-0162 | Crítica (9.8) | 0.67% | — | 9 feb 2022 | The vulnerability exists in TP-Link TL-WR841N V11 3.16.9 Build 160325 Rel.62500n wireless router due to transmission of authentication information in cleartextbase64 format. Successful exploitation of this vulnerability… |
| CVE-2020-35576 | Alta (8.8) | 42% | — | 26 ene 2021 | A Command Injection issue in the traceroute feature on TP-Link TL-WR841N V13 (JP) with firmware versions prior to 201216 allows authenticated users to execute arbitrary code as root via shell metacharacters, a different… |
| CVE-2020-8423 | Alta (7.2) | 9.3% | — | 2 abr 2020 | A buffer overflow in the httpd daemon on TP-Link TL-WR841N V10 (firmware version 3.16.9) devices allows an authenticated remote attacker to execute arbitrary code via a GET request to the page for the configuration of… |
| CVE-2019-17147 | Alta (8.8) | 14% | — | 7 ene 2020 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of TP-LINK TL-WR841N routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.