Description
TP-Link Archer AX21 (AX1800) firmware versions before 1.1.4 Build 20230219 contained a command injection vulnerability in the country form of the /cgi-bin/luci;stok=/locale endpoint on the web management interface. Specifically, the country parameter of the write operation was not sanitized before being used in a call to popen(), allowing an unauthenticated attacker to inject commands, which would be run as root, with a simple POST request.
In plain language
AI Act nowCVE-2023-1389 is a serious web-management bug in TP-Link Archer AX21 (AX1800) router firmware that lets an attacker run commands on your router without logging in; if your router is on firmware older than 1.1.4, you should act now.
CVE-2023-1389 is a command injection in TP-Link Archer AX21 (AX1800) firmware (untrusted input in the web management “country” handling for the /cgi-bin/luci;stok=/locale endpoint), enabling unauthenticated remote command execution as root; it is listed in CISA KEV with a remediation deadline of 2023-05-22.
What to do now
- Check your TP-Link Archer AX21 (AX1800) firmware version in the router’s web interface (or device label) and confirm whether it is older than 1.1.4.
- If it is older than 1.1.4, download and install the Archer AX21 firmware update that fixes CVE-2023-1389.
- After updating, reboot the router and verify the firmware version now shows 1.1.4 or newer.
- If you cannot update promptly, restrict access to the router’s web management interface (only from your local network) until the update is applied.
CVSS Vector Breakdown
AV:AAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply updates per vendor instructions.
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
- Ботнет Evooo1Bot превращает зараженные устройства в проксиru-ru·Хакер (xakep.ru)· Exploited Alcatel ddos-botnet
- Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxiesen·The Hacker News· Exploited Alcatel OmniPCX Enterprise ddos-botnet
- TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Developmenten-us·Palo Alto Unit 42· Research TuxBot v3 Evolution ddos-botnet
- CISA Expands Active Exploit Catalog with Cisco, Arista, and Chromium Flawsen-us·Daily CyberSecurity (securityonline.info)· Exploited Cisco Catalyst SD-WAN Manager zero-day
- 4th May – Threat Intelligence Reporten-us·Check Point Research· Roundup ShinyHunters data-breach
- Anti-DDoS Firm Heaped Attacks on Brazilian ISPsen-us·Krebs on Security· Exploited Archer AX21 routers ddos-botnet
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2023-1389 and every CVE in our database. Create a free account — no credit card required.
Create Free Account