CVE-2023-1389 is a critical command injection vulnerability affecting TP-Link Archer AX21 (AX1800) routers with firmware versions prior to 1.1.4 Build 20230219. This flaw allows an unauthenticated attacker to execute arbitrary commands as root via a simple POST request to the web management interface due to improper sanitization of the country parameter. With a CVSS score of 8.8 (HIGH), the vulnerability is easily exploitable over the network with no user interaction, leading to complete compromise of confidentiality, integrity, and availability. This CVE is actively exploited in the wild, listed in CISA's KEV catalog, and has publicly available exploit code, including Nuclei templates and an ExploitDB entry, with significant community discussion and media coverage highlighting its use by various botnets.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.1.4CPE matchmatch criteria | cpe:2.3:o:tp-link:archer_ax21_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Unauthenticated Command Injection in TP-Link Archer AX21 (AX1800)
Mar 14, 2023Unauthenticated Command Injection in TP-Link Archer AX21 (AX1800)
Mar 14, 2023Unauthenticated Command Injection in TP-Link Archer AX21 (AX1800)
Mar 14, 2023Unauthenticated Command Injection in TP-Link Archer AX21 (AX1800)
Mar 14, 2023Statement on Archer AX21 Remote Code Execution Vulnerability