TP-Link Archer AX-21 Command Injection Vulnerability
cve CVE-2023-1389 2 sources, 2 claims · Watch
CISA Known Exploited Vulnerabilities writes:
TP-Link Archer AX-21 Command Injection Vulnerability TP-Link Archer AX-21 contains a command injection vulnerability that allows for remote code execution. Apply updates per vendor instructions. https://www.tp-link.com/us/support/download/archer-ax21/v3/#Firmware; https://nvd.nist.gov/vuln/detail/CVE-2023-1389 the claim
TP-Link Archer AX-21 Command Injection Vulnerability TP-Link Archer AX-21 contains a command injection vulnerability that allows for remote code execution. Apply updates per vendor instructions. https://www.tp-link.com/us/support/download/archer-ax21/v3/#Firmware; https://nvd.nist.gov/vuln/detail/CVE-2023-1389 the claim
What each source says
| Property | Source | Said | Means here |
|---|---|---|---|
| Author author | Exploit-DB | Voyag3rreceipt
What the source handed over{
"aliases": "",
"application_url": "",
"author": "Voyag3r",
"codes": "CVE-2023-1389",
"date_added": "2023-08-10",
"date_published": "2023-08-10",
"date_updated": "2023-08-10",
"description": "TP-Link Archer AX21 - Unauthenticated Command Injection",
"file": "exploits/hardware/remote/51677.py",
"id": "51677",
"platform": "hardware",
"port": "",
"screenshot_url": "",
"source_url": "",
"tags": "",
"type": "remote",
"verified": "0"
} | — |
| Cwes cwes | CISA Known Exploited Vulnerabilities | CWE-77receipt
What the source handed over{
"cveID": "CVE-2023-1389",
"cwes": "CWE-77",
"dateAdded": "2023-05-01",
"dueDate": "2023-05-22",
"forensicTriage": "No",
"knownRansomwareCampaignUse": "Unknown",
"notes": "https://www.tp-link.com/us/support/download/archer-ax21/v3/#Firmware; https://nvd.nist.gov/vuln/detail/CVE-2023-1389",
"product": "Archer AX21",
"requiredAction": "Apply updates per vendor instructions.",
"shortDescription": "TP-Link Archer AX-21 contains a command injection vulnerability that allows for remote code execution.",
"vendorProject": "TP-Link",
"vulnerabilityName": "TP-Link Archer AX-21 Command Injection Vulnerability"
} | — |
| Due date due_date | CISA Known Exploited Vulnerabilities | 2023-05-22receipt
What the source handed over{
"cveID": "CVE-2023-1389",
"cwes": "CWE-77",
"dateAdded": "2023-05-01",
"dueDate": "2023-05-22",
"forensicTriage": "No",
"knownRansomwareCampaignUse": "Unknown",
"notes": "https://www.tp-link.com/us/support/download/archer-ax21/v3/#Firmware; https://nvd.nist.gov/vuln/detail/CVE-2023-1389",
"product": "Archer AX21",
"requiredAction": "Apply updates per vendor instructions.",
"shortDescription": "TP-Link Archer AX-21 contains a command injection vulnerability that allows for remote code execution.",
"vendorProject": "TP-Link",
"vulnerabilityName": "TP-Link Archer AX-21 Command Injection Vulnerability"
} | — |
| Exploited exploited | CISA Known Exploited Vulnerabilities | yesreceipt
What the source handed over{
"cveID": "CVE-2023-1389",
"cwes": "CWE-77",
"dateAdded": "2023-05-01",
"dueDate": "2023-05-22",
"forensicTriage": "No",
"knownRansomwareCampaignUse": "Unknown",
"notes": "https://www.tp-link.com/us/support/download/archer-ax21/v3/#Firmware; https://nvd.nist.gov/vuln/detail/CVE-2023-1389",
"product": "Archer AX21",
"requiredAction": "Apply updates per vendor instructions.",
"shortDescription": "TP-Link Archer AX-21 contains a command injection vulnerability that allows for remote code execution.",
"vendorProject": "TP-Link",
"vulnerabilityName": "TP-Link Archer AX-21 Command Injection Vulnerability"
} | — |
| Forensic triage forensic_triage | CISA Known Exploited Vulnerabilities | falsereceipt
What the source handed over{
"cveID": "CVE-2023-1389",
"cwes": "CWE-77",
"dateAdded": "2023-05-01",
"dueDate": "2023-05-22",
"forensicTriage": "No",
"knownRansomwareCampaignUse": "Unknown",
"notes": "https://www.tp-link.com/us/support/download/archer-ax21/v3/#Firmware; https://nvd.nist.gov/vuln/detail/CVE-2023-1389",
"product": "Archer AX21",
"requiredAction": "Apply updates per vendor instructions.",
"shortDescription": "TP-Link Archer AX-21 contains a command injection vulnerability that allows for remote code execution.",
"vendorProject": "TP-Link",
"vulnerabilityName": "TP-Link Archer AX-21 Command Injection Vulnerability"
} | — |
| Known ransomware campaign use known_ransomware_campaign_use | CISA Known Exploited Vulnerabilities | Unknownreceipt
What the source handed over{
"cveID": "CVE-2023-1389",
"cwes": "CWE-77",
"dateAdded": "2023-05-01",
"dueDate": "2023-05-22",
"forensicTriage": "No",
"knownRansomwareCampaignUse": "Unknown",
"notes": "https://www.tp-link.com/us/support/download/archer-ax21/v3/#Firmware; https://nvd.nist.gov/vuln/detail/CVE-2023-1389",
"product": "Archer AX21",
"requiredAction": "Apply updates per vendor instructions.",
"shortDescription": "TP-Link Archer AX-21 contains a command injection vulnerability that allows for remote code execution.",
"vendorProject": "TP-Link",
"vulnerabilityName": "TP-Link Archer AX-21 Command Injection Vulnerability"
} | — |
| Platform platform | Exploit-DB | hardwarereceipt
What the source handed over{
"aliases": "",
"application_url": "",
"author": "Voyag3r",
"codes": "CVE-2023-1389",
"date_added": "2023-08-10",
"date_published": "2023-08-10",
"date_updated": "2023-08-10",
"description": "TP-Link Archer AX21 - Unauthenticated Command Injection",
"file": "exploits/hardware/remote/51677.py",
"id": "51677",
"platform": "hardware",
"port": "",
"screenshot_url": "",
"source_url": "",
"tags": "",
"type": "remote",
"verified": "0"
} | — |
| Product product | CISA Known Exploited Vulnerabilities | Archer AX21receipt
What the source handed over{
"cveID": "CVE-2023-1389",
"cwes": "CWE-77",
"dateAdded": "2023-05-01",
"dueDate": "2023-05-22",
"forensicTriage": "No",
"knownRansomwareCampaignUse": "Unknown",
"notes": "https://www.tp-link.com/us/support/download/archer-ax21/v3/#Firmware; https://nvd.nist.gov/vuln/detail/CVE-2023-1389",
"product": "Archer AX21",
"requiredAction": "Apply updates per vendor instructions.",
"shortDescription": "TP-Link Archer AX-21 contains a command injection vulnerability that allows for remote code execution.",
"vendorProject": "TP-Link",
"vulnerabilityName": "TP-Link Archer AX-21 Command Injection Vulnerability"
} | — |
| Type type | Exploit-DB | remotereceipt
What the source handed over{
"aliases": "",
"application_url": "",
"author": "Voyag3r",
"codes": "CVE-2023-1389",
"date_added": "2023-08-10",
"date_published": "2023-08-10",
"date_updated": "2023-08-10",
"description": "TP-Link Archer AX21 - Unauthenticated Command Injection",
"file": "exploits/hardware/remote/51677.py",
"id": "51677",
"platform": "hardware",
"port": "",
"screenshot_url": "",
"source_url": "",
"tags": "",
"type": "remote",
"verified": "0"
} | — |
| Vendor project vendor_project | CISA Known Exploited Vulnerabilities | TP-Linkreceipt
What the source handed over{
"cveID": "CVE-2023-1389",
"cwes": "CWE-77",
"dateAdded": "2023-05-01",
"dueDate": "2023-05-22",
"forensicTriage": "No",
"knownRansomwareCampaignUse": "Unknown",
"notes": "https://www.tp-link.com/us/support/download/archer-ax21/v3/#Firmware; https://nvd.nist.gov/vuln/detail/CVE-2023-1389",
"product": "Archer AX21",
"requiredAction": "Apply updates per vendor instructions.",
"shortDescription": "TP-Link Archer AX-21 contains a command injection vulnerability that allows for remote code execution.",
"vendorProject": "TP-Link",
"vulnerabilityName": "TP-Link Archer AX-21 Command Injection Vulnerability"
} | — |
| Verified verified | Exploit-DB | falsereceipt
What the source handed over{
"aliases": "",
"application_url": "",
"author": "Voyag3r",
"codes": "CVE-2023-1389",
"date_added": "2023-08-10",
"date_published": "2023-08-10",
"date_updated": "2023-08-10",
"description": "TP-Link Archer AX21 - Unauthenticated Command Injection",
"file": "exploits/hardware/remote/51677.py",
"id": "51677",
"platform": "hardware",
"port": "",
"screenshot_url": "",
"source_url": "",
"tags": "",
"type": "remote",
"verified": "0"
} | — |
vulnerability
| TP-Link Archer AX-21 Command Injection Vulnerability zetlyn/cve-kev · 2023-05-01 | cwes CWE-77 due_date 2023-05-22 exploited yes forensic_triage false known_ransomware_campaign_use Unknown product Archer AX21 vendor_project TP-Link |
exploit
| TP-Link Archer AX21 - Unauthenticated Command Injection zetlyn/cve-exploitdb · 2023-08-10 | author Voyag3r platform hardware type remote verified false | source |