Executive brief
TP-Link Archer AX21 (AX1800) routers contain a command injection vulnerability in the country parameter of the /cgi-bin/luci;stok=/locale endpoint. An unauthenticated attacker can execute arbitrary commands as root via a specially crafted POST request due to improper sanitization before a popen() call.
Affected products
- TP-Link Archer AX21 (AX1800) firmware before 1.1.4 Build 20230219
Timeline
- 2023-03-15: disclosed: NVD Published Date
- 2023-05-01: kev added: Date added to CISA Known Exploited Vulnerabilities Catalog