CVE-2023-1389: TP-Link Archer AX-21 Command Injection Vulnerability

Published Mar 15, 2023
·
Updated

TP-Link Archer AX-21 contains a command injection vulnerability that allows for remote code execution.

Other sources

TP-Link Archer AX21 (AX1800) firmware versions before 1.1.4 Build 20230219 contained a command injection vulnerability in the country form of the /cgi-bin/luci;stok=/locale endpoint on the web management interface. Specifically, the country parameter of the write operation was not sanitized before being used in a call to popen(), allowing an unauthenticated attacker to inject commands, which would be run as root, with a simple POST request.

Credit

Voyag3r

Affected Software

5 affected components
TP-Link Archer AX21
TP-Link Archer Ax21 Firmware<1.1.4
TP-Link Archer AX21
All of the following
TP-Link Archer Ax21 Firmware<1.1.4
TP-Link Archer AX21

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade TP-Link Archer AX21 (AX1800) to a version that resolves this vulnerability.

    Fixed in 1.1.4 Build 20230219

Event History

Mar 15, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeaknessAffected Software
May 1, 2023
Known Exploited
via CISA·12:00 AM
Aug 10, 2023
Exploit Published
12:00 AM
Apr 17, 2024
News Published
via BleepingComputer·01:03 PM
News Published
via BleepingComputer·01:05 PM
Dec 20, 2024
News Published
via Dark Reading·05:23 PM
News Published
via Dark Reading·05:56 PM
Dec 24, 2024
News Published
via BleepingComputer·08:04 PM
Oct 9, 2025
News Published
via BleepingComputer·05:17 PM
Apr 22, 2026
News Published
via BleepingComputer·08:04 PM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the vulnerability ID for this TP-Link Archer AX-21 vulnerability?

The vulnerability ID for this TP-Link Archer AX-21 vulnerability is CVE-2023-1389.

2

What is the severity level of CVE-2023-1389?

The severity level of CVE-2023-1389 is high.

3

What is the affected software for CVE-2023-1389?

The affected software for CVE-2023-1389 is TP-Link Archer AX21 firmware versions before 1.1.4 Build 20230219.

4

What is the CWE number associated with CVE-2023-1389?

The CWE number associated with CVE-2023-1389 is CWE-77.

5

How can I fix CVE-2023-1389?

To fix CVE-2023-1389, update TP-Link Archer AX21 firmware to version 1.1.4 Build 20230219 or later.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203