Unauthenticated ated_tp Command Injection in TP-Link TL-WR841N Enables Root Code Execution

Note: This data is for reference and cybersecurity research purposes only.CyStack advises users not to use this information for unlawful purposes.

What is CVE-2023-39471?

CVE-2023-39471 is a vulnerability classified as Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'), affecting TL-WR841N (affected versions: 4.19). This vulnerability is rated High, with a CVSS score of 8.8. Current sources do not report this vulnerability as exploited.

Overview

Original source data

TP-Link TL-WR841N ated_tp Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link TL-WR841N routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the ated_tp service. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-21825.

Affected products and scope

The supported scope is:

  • TP-Link TL-WR841N: version 4.19 is marked affected in the normalized CNA facts.
  • Firmware listed by ZDI as fixed: TL-WR841N(US)_V14_231119. This is a specific US-variant firmware and does not establish that every TL-WR841N variant or every other release branch is unaffected.
  • ZDI also lists TL-WR840N(KR)_V6.20_231121 as fixed firmware. However, the supplied affected-product facts identify only TP-Link TL-WR841N, so whether TL-WR840N belongs to this record's affected scope is not independently established.

Technical details

The flaw is in the ated_tp service of TP-Link TL-WR841N. The service uses a user-supplied string in a system call without adequate validation of special elements, creating an OS command injection weakness classified as CWE-78.

The evidence supports the following high-level attack flow:

  1. A network-adjacent attacker supplies controlled data to a reachable component of the router.
  2. ated_tp passes the insufficiently validated string into a system call.
  3. Arbitrary code executes in the context of root.

The record does not disclose the specific request, parameter, protocol, or endpoint that must be reached. Do not infer a payload, path, or additional deployment condition beyond the presence of the affected component and network-adjacent reachability.

Exploitability

The vulnerability is reachable through a network-adjacent attack path and does not require authentication or user interaction. The normalized record describes the attack complexity as low, but it does not provide the specific request or protocol. The public_exploit field is false and known_exploited is null; this does not prove that exploitation has never occurred. The consulted ZDI material does not identify a public exploit, campaign, or specific indicator.

Technical impact

Exploitation can result in arbitrary code execution in the context of root on the affected TP-Link TL-WR841N router. The technical outcome can include loss of confidentiality, unauthorized modification of data or configuration, and loss of availability, consistent with the root-level execution described in the record.

The attack surface is limited to network-adjacent reachability, and the described scope is unchanged. The evidence does not establish access to other systems, persistence, or impact beyond the router; those consequences remain unknown.

Business impact

Successful exploitation of TP-Link TL-WR841N can give an attacker root-level code execution on the affected router. This could allow unauthorized changes to device state or configuration, disrupt routing functions, and affect the confidentiality, integrity, or availability of data handled by the router.

The confirmed scope is the vulnerable router. The available evidence does not establish whether exploitation enables movement into other systems on the network, so that consequence should not be treated as confirmed.

Remediation

  1. For a matching US variant, install TL-WR841N(US)_V14_231119, which ZDI lists as fixed. Confirm the model, region, and hardware branch before applying it because firmware for another variant should not be assumed compatible.
  2. If the device is TP-Link TL-WR840N, note that ZDI lists TL-WR840N(KR)_V6.20_231121 as fixed, but the normalized record does not mark that product as affected. Do not use that information to infer the status of TL-WR841N or other variants.
  3. If the listed firmware does not match the device, obtain model- and region-specific remediation from TP-Link. Do not infer that later or parallel branches are fixed solely because one fixed firmware is listed.
  4. While applicability or deployment is being confirmed, restrict untrusted adjacent-network access to the router as a precaution. This reduces exposure temporarily but does not replace fixed firmware.

Detection

Detection should focus on inventory, firmware, and service reachability:

  • Inventory TP-Link TL-WR841N routers, including model, hardware region, and current firmware; prioritize devices reporting version 4.19.
  • Determine whether the ated_tp service is present and reachable from adjacent networks. Do not assume that the service always produces a dedicated log.
  • Review available network telemetry and administrative logs for unusual interactions with the router from adjacent devices. No specific IOC or log signature has been established by the source.
  • After remediation, verify the actual firmware on each device and reconcile it with the exact model, region, and hardware branch. Lack of suspicious log evidence does not prove that a device is safe.
Sources (12)
Learn more

Run an in-depth assessment with complete web risk management

CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.

Explore CyStack VulnScan