FortiGuard
Fortinet’s Global Threat Intelligence and Research
Pwalia
Staff
Staff
Article Id 258448
Description TP-Link Archer AX21 (AX1800) firmware versions before 1.1.4 contains a command injection vulnerability in the web management interface specifically in the "Country" field. There is no sanitization of this field, so an attacker can exploit it for malicious activities and gain foothold. The vulnerability has been seen to be exploited in the wild to deploy Mirai botnet.
CVEs CVE-2023-1389
Severity Medium
Posted on May 23, 2023
Outbreak Report Link https://www.fortiguard.com/outbreak-alert/tp-link-archer-ax-21-command-injection
Contributors