KEVIntel
8.8
CVSS
High

CVE-2023-1389

PUBLISHED

TP-Link Archer AX21 (AX1800) firmware versions before 1.1.4 Build 20230219 contained a command injection vulnerability in the country form of the...

Exploited in the wild Low complexity No user interaction
Vendor
TP-Link
Product
TP-Link Archer AX21 (AX1800)
Published
Mar 15, 2023
EPSS

Description

TP-Link Archer AX21 (AX1800) firmware versions before 1.1.4 Build 20230219 contained a command injection vulnerability in the country form of the /cgi-bin/luci;stok=/locale endpoint on the web management interface. Specifically, the country parameter of the write operation was not sanitized before being used in a call to popen(), allowing an unauthenticated attacker to inject commands, which would be run as root, with a simple POST request.

windows cisa nuclei_scanner edge nessus_scanner

CVSS scores

CVSS v3.1 8.8 High

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Exploitation status

Exploited in the wild

Recorded 2025-04-26 00:00:00 UTC · Source

SSVC decision points

Exploitation
active
Automatable
Yes
Technical impact
total

Known exploited vulnerability sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
CISA May 01, 2023

Potential proof of concepts

These PoCs are unverified and could contain malware. Use at your own risk.

Terminal1337/CVE-2023-1389

github · Created 2023-09-09 15:53:22 UTC · 12 stars

TP-Link Archer AX21 - Unauthenticated Command Injection [Loader]

Voyag3r-Security/CVE-2023-1389

github · Created 2023-07-28 03:09:00 UTC · 11 stars

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Added to KEVIntel

  • Detected by Nessus

  • Detected by Nuclei