HIGH CISA KEV

CVE-2023-1389

CVSS v3

8.8

HIGH

EPSS Score

93.6%

exploit probability

CISA KEV

Yes

known exploited

Exploitation

SSVC status

Description

TP-Link Archer AX21 (AX1800) firmware versions before 1.1.4 Build 20230219 contained a command injection vulnerability in the country form of the /cgi-bin/luci;stok=/locale endpoint on the web management interface. Specifically, the country parameter of the write operation was not sanitized before being used in a call to popen(), allowing an unauthenticated attacker to inject commands, which would be run as root, with a simple POST request.

CISA Known Exploited Vulnerability

Date Added
5/1/2023
Patch Due Date
5/22/2023
Ransomware Use
Unknown

Technical details

Published
3/15/2023

Frequently asked questions

What is CVE-2023-1389?

TP-Link Archer AX21 (AX1800) firmware versions before 1.1.4 Build 20230219 contained a command injection vulnerability in the country form of the /cgi-bin/luci;stok=/locale endpoint on the web management interface. Specifically, the country parameter of the write operation was not sanitized before being used in a call to popen(), allowing an unauthenticated attacker to inject commands, which would be run as root, with a simple POST request.

Is CVE-2023-1389 actively exploited?

Yes. CVE-2023-1389 is on the CISA Known Exploited Vulnerabilities (KEV) catalog, meaning it has been confirmed as actively exploited in the wild. CISA requires federal agencies to patch by 5/22/2023.

What is the CVSS score for CVE-2023-1389?

CVE-2023-1389 has a CVSS v3 base score of 8.8 (HIGH severity).

Is CVE-2023-1389 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.