QID 730796
Date Published: 2023-05-10
QID 730796: TP-Link Archer AX21 (AX1800) Unauthenticated Command Injection Vulnerability
TP-Link Archer AX21 (AX1800) firmware versions before 1.1.4 Build 20230219 contained a command injection vulnerability in the country form of the /cgi-bin/luci;stok=/locale endpoint on the web management interface. Specifically, the country parameter of the write operation was not sanitized before being used in a call to popen(), allowing an unauthenticated attacker to inject commands, which would be run as root, with a simple POST request.
Affected Version:
TP-Link Archer AX21 (AX1800) firmware versions before 1.1.4 Build 20230219
QID Detection Logic (Unauthenticated):
This QID checks for vulnerable instances of TP-Link Archer AX21 (AX1800) by sending a crafted payload to the router. A vulnerable router will connect back to our scanner on a random port decided at the time of scanning, for confirming the command injection vulnerability.
Successful exploitation of the vulnerability may allow an attacker to execute arbitrary code remotely.
CVEs related to QID 730796
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| TP-Link Archer AX21 Firmware Download Page |
|