CVE Feed

    Dashboard / CVE / CVE-2023-1389

    CVE-2023-1389

    TP-Link Archer AX21 (AX1800) firmware versions before 1.1.4 Build 20230219 contained a command injection vulnerability in the country form of the /cgi-bin/luci;stok=/locale endpoint on the web management interface. Specifically, the country parameter of the write operation was not sanitized before being used in a call to popen(), allowing an unauthenticated attacker to inject commands, which would be run as root, with a simple POST request.

    Published:Mar 15, 2023
    Last Modified:Nov 3, 2025
    EPS:Mar 15, 2023
    EPSS Score:0.93659
    CVSS Score:8.8

    CISA Notification

    Description

    TP-Link Archer AX21 (AX1800) firmware versions before 1.1.4 Build 20230219 contained a command injection vulnerability in the country form of the /cgi-bin/luci;stok=/locale endpoint on the web management interface. Specifically, the country parameter of the write operation was not sanitized before being used in a call to popen(), allowing an unauthenticated attacker to inject commands, which would be run as root, with a simple POST request.

    Required Action:

    Apply updates per vendor instructions.

    Notes:

    No extra notes provided.

    Due Date
    May 22, 2023
    1208 days ago
    Alert Date
    May 1, 2023
    1229 days ago

    Affected Products

    Vendor
    Tp-link
    Product
    Archer Ax21
    Vendor
    Tp-link
    Product
    Archer Ax21 Firmware

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High