CVE Tools

Description

TP-Link Archer AX21 (AX1800) firmware versions before 1.1.4 Build 20230219 contained a command injection vulnerability in the country form of the /cgi-bin/luci;stok=/locale endpoint on the web management interface. Specifically, the country parameter of the write operation was not sanitized before being used in a call to popen(), allowing an unauthenticated attacker to inject commands, which would be run as root, with a simple POST request.

In plain language

AI Act now

CVE-2023-1389 is a serious web-management bug in TP-Link Archer AX21 (AX1800) router firmware that lets an attacker run commands on your router without logging in; if your router is on firmware older than 1.1.4, you should act now.

Executive summary

CVE-2023-1389 is a command injection in TP-Link Archer AX21 (AX1800) firmware (untrusted input in the web management “country” handling for the /cgi-bin/luci;stok=/locale endpoint), enabling unauthenticated remote command execution as root; it is listed in CISA KEV with a remediation deadline of 2023-05-22.

If affected, business impact
Router takeover and full controlTraffic interception or hijackingMalware persistence on the routerSite downtime from router disruption

What to do now

  1. Check your TP-Link Archer AX21 (AX1800) firmware version in the router’s web interface (or device label) and confirm whether it is older than 1.1.4.
  2. If it is older than 1.1.4, download and install the Archer AX21 firmware update that fixes CVE-2023-1389.
  3. After updating, reboot the router and verify the firmware version now shows 1.1.4 or newer.
  4. If you cannot update promptly, restrict access to the router’s web management interface (only from your local network) until the update is applied.
Usually a quick update

CVSS Vector Breakdown

AV:AAC:LPR:NUI:NS:UC:HI:HA:H
Exploitability
AV:AAttack Vector
Adjacent
AC:LAttack Complexity
Low
PR:NPrivileges Required
None
UI:NUser Interaction
None
Scope
S:UScope
Unchanged
Impact
C:HConfidentiality
High
I:HIntegrity
High
A:HAvailability
High

Weaknesses

Affected Products

and 1 more affected products View all →

Exploitability

CISA Known Exploited Vulnerability
Added to KEV:May 1, 2023
Remediation due:May 22, 2023

Required action: Apply updates per vendor instructions.

2 exploit sources identified

Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.

View exploit details
Official Patch Available

Attack Graph

Products CVE Techniques Tactics

Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/ + scroll to zoom, or go fullscreen.

MITRE ATT&CK

1 technique
Execution
View detailed technique mapping

References

and 3 more references View all →
6

Unlock Complete Vulnerability Intelligence

Get the full picture for CVE-2023-1389 and every CVE in our database. Create a free account — no credit card required.

Create Free Account
Plain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows