CVE-2017-9466: TP-Link WR841N v8 Firmware
Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.
The executable httpd on the TP-Link WR841N V8 router before TL-WR841N(UN)_V8_170210 contained a design flaw in the use of DES for block encryption. This resulted in incorrect access control, which allowed attackers to gain read-write access to system settings through the protected router configuration service tddp via the LAN and Ath0 (Wi-Fi) interfaces.
Affected products
- TP-Link WR841N v8 Firmware: up to and including tl-wr841n_v8_140724
Published 2017-06-26. Last modified 2026-06-17.