CVE-2023-1389 | TP-Link Archer AX21 prior 1.1.4 Build 20230219 Web Management Interface locale popen country os command injection (EDB-51677)
A vulnerability classified as very critical was found in TP-Link Archer AX21. This vulnerability affects the function popen of the file /cgi-bin/luci;stok=/locale of the component Web Management Interface. The manipulation of the argument country leads to os command injection.
This vulnerability was named CVE-2023-1389. The attack can be initiated remotely. Furthermore, there is an exploit available.
A worm is spreading, which is automatically exploiting this vulnerability.
It is recommended to upgrade the affected component.