CrowdSec
6/10CrowdSec Score

TP-Link Archer AX21 - RCE (CVE-2023-1389)

Published on15-03-2023
First seen on23-11-2024

788Exploiting IPs reported

TP-Link Archer AX21 (AX1800) firmware versions before 1.1.4 Build 20230219 contained a command injection vulnerability in the country form of the /cgi-bin/luci;stok=/locale endpoint on the web management interface. Specifically, the country parameter of the write operation was not sanitized before being used in a call to popen(), allowing an unauthenticated attacker to inject commands, which would be run as root, with a simple POST request.

CrowdSec analysis

CVE-2023-1389 is a command injection vulnerability found in the web management interface of certain TP-Link Archer devices, allowing unauthenticated attackers to execute commands with root privileges via unsanitized input.

CrowdSec has been tracking this vulnerability and its exploits since 15th of December 2023.

According to CrowdSec data, while opportunistic exploitation dominates, a portion of threat actors trying to exploit CVE-2023-1389 apply basic targeting methods such as port or service detection. This indicates emerging patterns of selective targeting. CrowdSec data also reveals a clear uptick in attacks involving CVE-2023-1389 over the past week. Activity is above the usual baseline, suggesting growing attention from attackers. This may reflect rising awareness, recent exploit releases, or expanded targeting efforts.

Observed exploitation attempts focus on URLs containing the /cgi-bin/luci/;stok=/locale path.

Exploitation

Get real-time information about exploitation attempts and actors involved.

Detected IPs

Discover the IPs that targeted this vulnerability across the CrowdSec Network.

Protection

Find out relevant information to protect your stack against this CVE.

Blocklist

With our advanced worldwide network detection, CrowdSec can provide a list of IPs known for exploiting the vulnerability.

To increase your protection against this CVE, block exploitation attempts with this list of identified actors.