CVE Intel / CVE-2023-1389

CVE-2023-1389

archer ax21 · tp-link
CISA KEVexploited on our sensorsHigh network detectable

What it is

TP-Link Archer AX21 (AX1800) firmware versions before 1.1.4 Build 20230219 contained a command injection vulnerability in the country form of the /cgi-bin/luci;stok=/locale endpoint on the web management interface. Specifically, the country parameter of the write operation was not sanitized before being used in a call to popen(), allowing an unauthenticated attacker to inject commands, which would be run as root, with a simple POST request.

Live exploitation on the huntback network (30 days)

13
attempts captured
4
distinct source IPs
2026-09-22
last seen
huntback carries a network signature for this CVE. Exploitation attempts are detected on the decoy fleet in real time.

How huntback helps

Deploy a decoy that emulates archer ax21 and you will see every attempt at this CVE the moment it lands, with the full payload, the attacker's infrastructure, and any stage-2 loader. Then huntback can scan the attacker back.

CVSSn/a High
EPSS1.00 (99% pct)
In CISA KEVyes
Publishedn/a
Network detectableyes, signatured