<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>WildforTech Security Advisories — TP-Link</title><description>Actively exploited vulnerabilities affecting TP-Link products.</description><link>https://wildfortech.com</link><atom:link href="https://wildfortech.com/security/vendor/tp-link.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2023-50224 — TP-Link TL-WR841N Authentication Bypass by Spoofing Vulnerability</title><link>https://wildfortech.com/security#CVE-2023-50224</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2023-50224</guid><description>The TP-Link TL-WR841N router contains a flaw in its built-in web server (httpd) that allows an attacker to bypass authentication through spoofing, potentially exposing credentials stored on the device. Because this service listens on TCP port 80 by default, the attack surface is the router&apos;s standard management interface. This is especially concerning because the device may be at end-of-life, meaning no vendor-supported fix is likely forthcoming.</description><pubDate>Wed, 03 Sep 2025 00:00:00 GMT</pubDate><category>TP-Link</category><category>TL-WR841N</category></item><item><title>CVE-2025-9377 — TP-Link Archer C7(EU) and TL-WR841N/ND(MS) OS Command Injection Vulnerability</title><link>https://wildfortech.com/security#CVE-2025-9377</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2025-9377</guid><description>TP-Link Archer C7(EU) and TL-WR841N/ND(MS) routers contain an OS command injection flaw in the Parental Control page, meaning an attacker who can reach that interface could execute arbitrary operating system commands on the device. Because these products are likely end-of-life or end-of-service, TP-Link may not issue a patch, leaving the vulnerability permanently unresolved. Compromised routers can be used to intercept traffic, pivot into internal networks, or join botnets.</description><pubDate>Wed, 03 Sep 2025 00:00:00 GMT</pubDate><category>TP-Link</category><category>Multiple Routers</category></item><item><title>CVE-2020-24363 — TP-link TL-WA855RE Missing Authentication for Critical Function Vulnerability</title><link>https://wildfortech.com/security#CVE-2020-24363</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2020-24363</guid><description>This vulnerability in the TP-Link TL-WA855RE range extender allows anyone on the same network to send an unauthenticated request that factory-resets the device. Once reset, an attacker can set a new admin password and take full control. Because no login is required to trigger the reset, any network user — or attacker who has gained local network access — can effectively seize administrative ownership of the device, disrupting connectivity and potentially pivoting further into the network.</description><pubDate>Tue, 02 Sep 2025 00:00:00 GMT</pubDate><category>TP-Link</category><category>TL-WA855RE</category></item><item><title>CVE-2023-33538 — TP-Link Multiple Routers Command Injection Vulnerability</title><link>https://wildfortech.com/security#CVE-2023-33538</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2023-33538</guid><description>Several older TP-Link routers contain a command injection flaw in their wireless network management interface, allowing an attacker to execute arbitrary operating system commands on the device. Because these models are likely end-of-life or end-of-service, TP-Link is not expected to release patches. A compromised router gives attackers a foothold into every device on that network, making this a serious threat for any organization still running this aging hardware.</description><pubDate>Mon, 16 Jun 2025 00:00:00 GMT</pubDate><category>TP-Link</category><category>Multiple Routers</category></item></channel></rss>