CVE-2023-1389: TP-Link Archer AX-21 Command Injection Vulnerability
TP-Link Archer AX-21 contains a command injection vulnerability that allows for remote code execution.
Other sources
TP-Link Archer AX21 (AX1800) firmware versions before 1.1.4 Build 20230219 contained a command injection vulnerability in the country form of the /cgi-bin/luci;stok=/locale endpoint on the web management interface. Specifically, the country parameter of the write operation was not sanitized before being used in a call to popen(), allowing an unauthenticated attacker to inject commands, which would be run as root, with a simple POST request.
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
TP-Link Archer AX21 (AX1800)to a version that resolves this vulnerability.Fixed in 1.1.4 Build 20230219
Event History
Frequently Asked Questions
What is the vulnerability ID for this TP-Link Archer AX-21 vulnerability?
The vulnerability ID for this TP-Link Archer AX-21 vulnerability is CVE-2023-1389.
What is the severity level of CVE-2023-1389?
The severity level of CVE-2023-1389 is high.
What is the affected software for CVE-2023-1389?
The affected software for CVE-2023-1389 is TP-Link Archer AX21 firmware versions before 1.1.4 Build 20230219.
What is the CWE number associated with CVE-2023-1389?
The CWE number associated with CVE-2023-1389 is CWE-77.
How can I fix CVE-2023-1389?
To fix CVE-2023-1389, update TP-Link Archer AX21 firmware to version 1.1.4 Build 20230219 or later.