Vulnerability record · CVE-2023-1389 · published 15 March 2023
CVE-2023-1389: TP-Link Archer AX21 web interface command injection via country parameter
Tp Link · Archer Ax21 Firmware
The /cgi-bin/luci;stok=/locale endpoint on the TP-Link Archer AX21 (AX1800) web management interface fails to sanitize the country parameter before passing it to popen(). Firmware versions before 1.1.4 Build 20230219 are affected, and the injected commands execute as root.
Description
TP-Link Archer AX21 (AX1800) firmware versions before 1.1.4 Build 20230219 contained a command injection vulnerability in the country form of the /cgi-bin/luci;stok=/locale endpoint on the web management interface. Specifically, the country parameter of the write operation was not sanitized before being used in a call to popen(), allowing an unauthenticated attacker to inject commands, which would be run as root, with a simple POST request.
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated root command injection on an internet-adjacent router, listed in CISA KEV with near-maximum EPSS and public exploit references.
What it is
The /cgi-bin/luci;stok=/locale endpoint on the TP-Link Archer AX21 (AX1800) web management interface fails to sanitize the country parameter before passing it to popen(). Firmware versions before 1.1.4 Build 20230219 are affected, and the injected commands execute as root.
Impact
An attacker can run arbitrary commands as root on the router, giving full control of the device, its configuration and any traffic it handles.
Attack surface
Reachable over the adjacent network via a simple POST request to the web management interface; no authentication or user interaction is required per the CVSS vector (AV:A/PR:N/UI:N).
Exploitation
CISA added it to KEV on 2023-05-01 with a 2023-05-22 remediation due, EPSS 30-day probability is 0.99999, and references carry Exploit tags, so exploitation is confirmed and widespread.
What to do
- Update Archer AX21 firmware to 1.1.4 Build 20230219 or later per vendor instructions.
- If patching is not immediately possible, disable remote/adjacent management access and restrict the web UI to trusted networks.
- Segment or isolate the router's management interface from untrusted network segments.
- Monitor for and block POST requests to /cgi-bin/luci;stok=/locale with suspicious country parameter values.
Detection
- Inspect web logs and network traffic for POST requests to /cgi-bin/luci;stok=/locale with shell metacharacters in the country parameter.
- Alert on unexpected outbound connections or processes spawned by the router's web management service.
- Hunt for command strings or reverse-shell patterns in router logs and traffic originating from the device.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2023-1389 to the Known Exploited Vulnerabilities catalog on 1 May 2023 as "TP-Link Archer AX-21 Command Injection Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 22 May 2023.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/174131/TP-Link-Archer-AX21-Command-Injection.html | ExploitThird Party AdvisoryVDB Entry |
| https://www.tenable.com/security/research/tra-2023-11 | ExploitThird Party Advisory |
| http://packetstormsecurity.com/files/174131/TP-Link-Archer-AX21-Command-Injection.html | ExploitThird Party AdvisoryVDB Entry |
| https://www.tenable.com/security/research/tra-2023-11 | ExploitThird Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-1389 | US Government Resource |
Track CVE-2023-1389 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-1389), CISA KEV, FIRST EPSS (scores of 2026-09-16). This page is refreshed as NVD updates the record.