CVE-2023-50224
Known exploited · CISA KEV
CVSS 6.5 MEDIUM: tP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure Vulnerability. EPSS 16% (97th percentile).
CISA federal remediation date Sep 24 · date passed
Policy · 19h ago
Four more U.S. states sued TP-Link on Oct. 6, bringing the total to five, while 21 state attorneys general separately pressed the FCC over the company’s U.S. approval bid. The complaints say TP-Link overstated both router security and its separation from China; TP-Link says it will fight the claims.
The filings point to public firmware flaws, including CVE-2023-50224 and CVE-2025-30237, and to end-of-life models as evidence that the company’s security marketing did not match the product reality. That matters because the bugs are no longer just patch notes for owners; they are now being used as proof in consumer-protection and regulatory arguments about what buyers were told.
For ISPs, resellers, and procurement teams, the exposure now includes approval fights and advertising claims, not only the routers behind the customer edge. If a vendor’s security story depends on firmware that is publicly documented as flawed, the legal and supply-chain fallout can outlast any fix.
Known exploited · CISA KEV
CVSS 6.5 MEDIUM: tP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure Vulnerability. EPSS 16% (97th percentile).
CISA federal remediation date Sep 24 · date passed
EPSS 0.3% (23rd percentile).
3 sources covering this story
TP-Link Sued by Four More U.S. States Over Router Security and China Ties
states sued TP-Link over allegedly misleading claims about router security and China ties, as 21 attorneys general contacted the FCC.
TP-Link Faces State Lawsuits and New Scrutiny Over ISP Router Flaws
SEC Consult has published technical details on vulnerabilities mentioned in a complaint filed by several US states.
US states sue popular kitmaker TP-Link over China risks
Router maker rejects allegations it misled buyers about protection and its reliance on Chinese suppliers
Part of the PlainSec briefing for 2026-10-10