← Vulnerability feed

Vulnerability record · CVE-2023-1389 · published 15 March 2023

CVE-2023-1389: TP-Link Archer AX21 web interface command injection via country parameter

Tp Link · Archer Ax21 Firmware

The /cgi-bin/luci;stok=/locale endpoint on the TP-Link Archer AX21 (AX1800) web management interface fails to sanitize the country parameter before passing it to popen(). Firmware versions before 1.1.4 Build 20230219 are affected, and the injected commands execute as root.

8.8 CVSS 3.1 High CISA KEV since 1 May 2023 EPSS 100% · top 0.1% CWE-77 · Command injection
8.8CVSS 3.1 base score
100%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
5References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

TP-Link Archer AX21 (AX1800) firmware versions before 1.1.4 Build 20230219 contained a command injection vulnerability in the country form of the /cgi-bin/luci;stok=/locale endpoint on the web management interface. Specifically, the country parameter of the write operation was not sanitized before being used in a call to popen(), allowing an unauthenticated attacker to inject commands, which would be run as root, with a simple POST request.

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityUnauthenticated root command injection on an internet-adjacent router, listed in CISA KEV with near-maximum EPSS and public exploit references.

What it is

The /cgi-bin/luci;stok=/locale endpoint on the TP-Link Archer AX21 (AX1800) web management interface fails to sanitize the country parameter before passing it to popen(). Firmware versions before 1.1.4 Build 20230219 are affected, and the injected commands execute as root.

Impact

An attacker can run arbitrary commands as root on the router, giving full control of the device, its configuration and any traffic it handles.

Attack surface

Reachable over the adjacent network via a simple POST request to the web management interface; no authentication or user interaction is required per the CVSS vector (AV:A/PR:N/UI:N).

Exploitation

CISA added it to KEV on 2023-05-01 with a 2023-05-22 remediation due, EPSS 30-day probability is 0.99999, and references carry Exploit tags, so exploitation is confirmed and widespread.

What to do

  • Update Archer AX21 firmware to 1.1.4 Build 20230219 or later per vendor instructions.
  • If patching is not immediately possible, disable remote/adjacent management access and restrict the web UI to trusted networks.
  • Segment or isolate the router's management interface from untrusted network segments.
  • Monitor for and block POST requests to /cgi-bin/luci;stok=/locale with suspicious country parameter values.

Detection

  • Inspect web logs and network traffic for POST requests to /cgi-bin/luci;stok=/locale with shell metacharacters in the country parameter.
  • Alert on unexpected outbound connections or processes spawned by the router's web management service.
  • Hunt for command strings or reverse-shell patterns in router logs and traffic originating from the device.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2023-1389 to the Known Exploited Vulnerabilities catalog on 1 May 2023 as "TP-Link Archer AX-21 Command Injection Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 22 May 2023.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-1389 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-31710Tp-link archer ax21 firmware out-of-bounds write vulnerabilityTP-Link Archer AX21(US)_V3_1.1.4 Build 20230219 and AX21(US)_V3.6_1.1.4 Build 20230219 are vulnerable to Buffer Overflow.EPSS 0.70%8.8CVE-2023-27346Tp-link archer ax21 firmware stack-based buffer overflow vulnerabilityTP-Link AX1800 Firmware Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers…EPSS 0.71%8.8CVE-2023-27332Tp-link archer ax21 firmware stack-based buffer overflow vulnerabilityTP-Link Archer AX21 tdpServer Logging Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent att…EPSS 0.72%8.1CVE-2023-27359Tp-link archer ax21 firmware race condition vulnerabilityTP-Link AX1800 hotplugd Firewall Rule Race Condition Vulnerability. This vulnerability allows remote attackers to gain access to LAN-side services on…EPSS 1.2%6.8CVE-2023-27333Tp-link archer ax21 firmware stack-based buffer overflow vulnerabilityTP-Link Archer AX21 tmpServer Command 0x422 Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjace…EPSS 0.74%9.8CVE-2026-8037Progress LoadMaster API OS Command Injection RCEProgress LoadMaster (and related ADC products) contain an OS command injection flaw in multiple API command endpoints where unsanitized input is pass…KEVEPSS 77%analysed8.7CVE-2026-42271LiteLLM MCP test endpoints allow authenticated OS command injectionLiteLLM versions 1.74.2 through before 1.83.7 expose two MCP preview endpoints (POST /mcp-rest/test/connection and POST /mcp-rest/test/tools/list) th…KEVEPSS 13%analysed7.2CVE-2025-29635D-Link DIR-823X command injection in set_prohibiting handlerD-Link DIR-823X firmware (240126 and 240802) contains a command injection flaw in the /goform/set_prohibiting POST handler. An attacker who already h…KEVEPSS 88%analysed

Source: NIST National Vulnerability Database (record CVE-2023-1389), CISA KEV, FIRST EPSS (scores of 2026-09-16). This page is refreshed as NVD updates the record.