LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2023-1389: TP-Link Archer AX-21 Command Injection Vulnerability

RBRecent Breaches Vulnerability Intelligence·May 1, 2023
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
May 22, 2023
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2023-1389 to its Known Exploited Vulnerabilities catalog on May 1, 2023, with a federal patch deadline of May 22, 2023 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

TP-Link Archer AX-21 contains a command injection vulnerability that allows for remote code execution.

CVE-2023-1389 is a command injection vulnerability in the TP-Link Archer AX21 router that can allow an attacker to achieve remote code execution. For IT and security teams, this matters because a compromised edge router can give an adversary a foothold on the network perimeter, potentially enabling further lateral movement or interception of traffic. Public detail is limited to the product and weakness class; confirm exact impact and conditions against the vendor advisory.

How it works

The flaw is classified as CWE-77 (command injection). In this class of weakness, user-controlled input reaches a shell or system command without proper sanitization or validation. An attacker who can reach the vulnerable interface can inject additional commands that the device then executes with the privileges of the affected process. The CISA summary states that the TP-Link Archer AX-21 contains a command injection vulnerability that allows for remote code execution. Specific exploit mechanics, required authentication, or exact attack vectors are not provided in the available facts and must be confirmed against the vendor advisory; do not assume unauthenticated access or particular payloads without that confirmation.

Am I affected? How to find it in your systems

The affected product is the TP-Link Archer AX21 (also referred to as Archer AX-21). These devices typically sit at the network edge as consumer or small-office Wi-Fi routers providing internet access, NAT, and wireless connectivity. Inventory efforts should focus on:

Telemetry signs of exploitation for this class of issue may include unexpected process spawning, unusual outbound connections from the router, or anomalous administrative activity. Router logs are often limited; if available, look for command-related errors or unexpected reboots. Confirm any indicators against the vendor advisory and your own baseline monitoring.

How to remediate

Patch first. CISA’s required action is to apply updates per vendor instructions. Obtain the fixed firmware or software update directly from TP-Link for the Archer AX21 and install it following the vendor’s documented procedure. After updating, verify the new firmware version is running and re-check the device configuration for any unauthorized changes.

Beyond the patch, apply standard hardening for this product class:

Confirm all version-specific remediation steps and any additional vendor-recommended configuration changes against the official advisory.

If you can't patch immediately

Until the vendor update can be applied, reduce exposure with compensating controls appropriate to a command-injection risk on a perimeter router:

These measures lower risk but do not replace the patch. Schedule the official update as soon as operationally feasible.

If your data may have been exposed

Actively exploited vulnerabilities of this type can lead to device compromise and subsequent network breaches. Known ransomware use is not documented for this CVE. If you suspect the router was compromised, treat it as a potential incident: isolate the device, preserve available logs, rotate credentials that may have traversed the router, and review internal systems for signs of follow-on activity. You can also run a free exposure scan of your email addresses against known breach data sets to check whether credentials or personal information associated with your organization have appeared in public breach collections.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedTP-Link · Archer AX21
WeaknessCWE-77
Added to CISA KEVMay 1, 2023
Federal patch deadlineMay 22, 2023
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities