Description
TP-Link Archer AX21 (AX1800) firmware versions before 1.1.4 Build 20230219 contained a command injection vulnerability in the country form of the /cgi-bin/luci;stok=/locale endpoint on the web management interface. Specifically, the country parameter of the write operation was not sanitized before being used in a call to popen(), allowing an unauthenticated attacker to inject commands, which would be run as root, with a simple POST request.
CVSS Vector Breakdown
AV:AAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply updates per vendor instructions.
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
- TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Developmenten-us·Palo Alto Unit 42· Research TuxBot v3 Evolution ddos-botnet
- CISA Expands Active Exploit Catalog with Cisco, Arista, and Chromium Flawsen-us·Daily CyberSecurity (securityonline.info)· Exploited Cisco Catalyst SD-WAN Manager zero-day
- 4th May – Threat Intelligence Reporten-us·Check Point Research· Roundup ShinyHunters data-breach
- Anti-DDoS Firm Heaped Attacks on Brazilian ISPsen-us·Krebs on Security· Exploited Archer AX21 routers ddos-botnet
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2023-1389 and every CVE in our database. Create a free account — no credit card required.
Create Free Account