peter bassill · operator
$ cve CVE-2023-1389 JSON

CVE-2023-1389 KEV EXPLOIT

8.8
HIGH · CVSS 3.1 · EPSS 100% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2023-05-22.

Description

TP-Link Archer AX21 (AX1800) firmware versions before 1.1.4 Build 20230219 contained a command injection vulnerability in the country form of the /cgi-bin/luci;stok=/locale endpoint on the web management interface. Specifically, the country parameter of the write operation was not sanitized before being used in a call to popen(), allowing an unauthenticated attacker to inject commands, which would be run as root, with a simple POST request.

Scoring

CVSS8.8 (HIGH, v3.1)
VectorCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS100% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-77
On CISA KEVyes — remediate by 2023-05-22
Public exploityes
Published2023-03-15
Last modified2026-06-17

CISA KEV

NameTP-Link Archer AX-21 Command Injection Vulnerability
Added2023-05-01
Due2023-05-22
Vendor / productTP-Link / Archer AX21
Ransomware usenone reported

Affected (2)

VendorProduct
tp-linkarcher ax21
tp-linkarcher ax21 firmware

Public exploits

SourceTitleDate
exploit-dbTP-Link Archer AX21 - Unauthenticated Command Injection2023-08-10

References

→ the Explorer  ·  watch your stack  ·  NVD