PromptRiskDBThreat intelligence atlas

CVE-2023-1389 - TP-Link Archer AX21

AI Vulnerability Context

TP-Link Archer AX21 (AX1800) firmware versions before 1.1.4 Build 20230219 contained a command injection vulnerability in the country form of the /cgi-bin/luci;stok=/locale endpoint on the web management interface. Specifically, the country parameter of the write operation was not sanitized before being used in a call to popen(), allowing an unauthenticated attacker to inject commands, which would be run as root...

Overview

A source-backed snapshot of this vulnerability.

TP-Link Archer AX21 (AX1800) firmware versions before 1.1.4 Build 20230219 contained a command injection vulnerability in the country form of the /cgi-bin/luci;stok=/locale endpoint on the web management interface. Specifically, the country parameter of the write operation was not sanitized before being used in a call to popen(), allowing an unauthenticated attacker to inject commands, which would be run as root, with a simple POST request.

CISA KEVyesWhether CISA lists this as exploited.
Techniques0AI attack methods connected to this vulnerability.
Case studies0Examples where this vulnerability is mentioned.

Vulnerability status

How serious this vulnerability is and whether it is known to be exploited.

CISA KEVHIGH
CVE ID
CVE-2023-1389
Vendor/project
TP-Link
Product
Archer AX21
Vulnerability name
TP-Link Archer AX-21 Command Injection Vulnerability
Date added
2023-05-01
Due date
2023-05-22
Known ransomware campaign use
Unknown
CVSS v3
8.8
CWE-77

Exploit context

What the vulnerability is about.

TP-Link Archer AX21 (AX1800) firmware versions before 1.1.4 Build 20230219 contained a command injection vulnerability in the country form of the /cgi-bin/luci;stok=/locale endpoint on the web management interface. Specifically, the country parameter of the write operation was not sanitized before being used in a call to popen(), allowing an unauthenticated attacker to inject commands, which would be run as root, with a simple POST request.

Source evidence

Original public records and references for this page.

Original source

Original source links

Open the public records and source datasets used for this page.