CVE-2023-1389 — TP-Link Archer AX-21 Command Injection Vulnerability
2023-05-01 • CISA Known Exploited Vulnerability
[event] TP-Link Archer AX-21 contains a command injection vulnerability that allows for remote code execution.
> AFFECTED SOFTWARE
| Field | Value |
|---|---|
| Vendor | TP-Link |
| Product | Archer AX21 |
| CWE | CWE-77 |
| CVE ID | CVE-2023-1389 |
| Date Added | 2023-05-01 |
| Due Date | 2023-05-22 |
| Ransomware Campaign | Unknown |
> MITIGATION
Apply updates per vendor instructions.
Due Date: 2023-05-22