kevmap

Coverage › CVE-2023-1389

CVE-2023-1389 Mapped Sigma

TP-Link Archer AX-21 Command Injection Vulnerability

Vendor / product
TP-Link — Archer AX21
Description (CISA)
TP-Link Archer AX-21 contains a command injection vulnerability that allows for remote code execution.
Added to KEV
2023-05-01
Due date
2023-05-22
Required action
Apply updates per vendor instructions.
Known ransomware use
Unknown
CWE
CWE-77
CISA notes
https://www.tp-link.com/us/support/download/archer-ax21/v3/#Firmware
https://nvd.nist.gov/vuln/detail/CVE-2023-1389
Elsewhere
cve.org · NVD · CISA KEV · JSON

ATT&CK techniques · CTID Mappings Explorer, ATT&CK 16.1, KEV snapshot 2025-07-28

5 mapping objects across 5 techniques. exploitation technique states how the vulnerability is exploited; primary and secondary impact state what exploitation achieves. They are different claims and are labelled as such.

TechniqueMapping typeCTID commentStatus in v19.2
T1106 Native API exploitation technique CVE-2023-1389 is a command injection vulnerability in one of the API components within the TP-Link Archer router’s web management interface. Public reports have reported that multiple botnet malware under the Mirai variants, including Condi, are targeting these vulnerable devices.
ref 1 · ref 2 · ref 3
live
T1041 Exfiltration Over C2 Channel secondary impact CVE-2023-1389 is a command injection vulnerability in one of the API components within the TP-Link Archer router’s web management interface. Public reports have reported that multiple botnet malware under the Mirai variants, including Condi, are targeting these vulnerable devices.
ref 1 · ref 2 · ref 3
live
T1070 Indicator Removal secondary impact CVE-2023-1389 is a command injection vulnerability in one of the API components within the TP-Link Archer router’s web management interface. Public reports have reported that multiple botnet malware under the Mirai variants, including Condi, are targeting these vulnerable devices.
ref 1 · ref 2 · ref 3
live
T1496 Resource Hijacking primary impact CVE-2023-1389 is a command injection vulnerability in one of the API components within the TP-Link Archer router’s web management interface. Public reports have reported that multiple botnet malware under the Mirai variants, including Condi, are targeting these vulnerable devices.
ref 1 · ref 2 · ref 3
live
T1498 Network Denial of Service secondary impact CVE-2023-1389 is a command injection vulnerability in one of the API components within the TP-Link Archer router’s web management interface. Public reports have reported that multiple botnet malware under the Mirai variants, including Condi, are targeting these vulnerable devices.
ref 1 · ref 2 · ref 3
live

Detection chain · ATT&CK Enterprise v19.2 detection strategies, analytics, log sources

T1041 Exfiltration Over C2 Channel secondary impact

Sigma rules tagged attack.t1041 (5)

Author: Florian Roth (Nextron Systems) · 2024-05-31 · logsource: product=windows category=network_connection · 07837ab9-60e1-481f-a74d-c31fb496a94c
Detects an executable accessing the portmap.io domain, which could be a sign of forbidden C2 traffic or data exfiltration by malicious actors
Techniques: T1041T1090.002
Author: Florian Roth (Nextron Systems) · 2017-04-15 (modified 2021-11-27) · logsource: category=firewall · 881834a4-6659-4773-821e-1c151789d873
Detects communication to C2 servers mentioned in the operational notes of the ShadowBroker leak of EquationGroup C2 tools
Techniques: T1041
Author: Security Onion Solutions · 2024-03-08 · logsource: product=opencanary category=application · b4e6b016-a2ac-4759-ad85-8000b300d61e
Detects instances where a TFTP service on an OpenCanary node has had a request.
Techniques: T1041
Author: Daniil Yugoslavskiy, oscd.community · 2019-10-24 (modified 2024-01-18) · logsource: product=windows category=process_creation · c75309a3-59f8-4a8d-9c2c-4c927ad50555
Detects the execution of well known tools that can be abused for data exfiltration and tunneling.
Author: Swachchhanda Shrawan Poudel (Nextron Systems) · 2025-09-24 · logsource: product=linux category=process_creation · efd2eb09-b72e-4a61-8dc7-b1382a1e8983
Detects potential Shai Hulud NPM package attack attempting to exfiltrate data via curl to external webhook sites.
Techniques: T1041T1005

T1070 Indicator Removal secondary impact

Sigma rules tagged attack.t1070 (20)

Author: Swachchhanda Shrawan Poudel (Nextron Systems) · 2025-09-02 · logsource: product=windows category=process_creation · 0649be4a-aeb0-45b0-b89e-7f1668f6d9c0
Detects attempts to delete Internet Information Services (IIS) log files via command line utilities, which is a common defense evasion technique used by attackers to cover their tracks. Threat actors often abuse vulnerabilities in web applications hosted on IIS servers to gain initial access and later delete IIS logs to evade detection.
Techniques: T1070
Author: Christian Burkard (Nextron Systems) · 2021-10-19 (modified 2023-02-08) · logsource: product=windows category=registry_delete · 07bdd2f5-9c58-4f38-aec8-e101bb79ef8d
Detects the deletion of registry keys containing the MSTSC connection history
Techniques: T1070T1112
Author: Christian Burkard (Nextron Systems) · 2021-08-27 (modified 2023-01-23) · logsource: product=windows service=msexchange-management · 09570ae5-889e-43ea-aac0-0e1221fb3d95
Detects removal of an exported Exchange mailbox which could be to cover tracks from ProxyShell exploit
Techniques: T1070
Author: Nasreddine Bencherchali (Nextron Systems) · 2022-06-28 (modified 2022-11-25) · logsource: product=windows category=ps_script · 115fdba9-f017-42e6-84cf-d5573bf2ddf8
Detects usage of powershell cmdlets to disable or remove ETW trace sessions
Techniques: T1070T1685
Author: Janantha Marasinghe · 2022-12-13 (modified 2022-12-28) · logsource: product=aws service=cloudtrail · 20f754db-d025-4a8f-9d74-e0037e999a9a
Detects an instance of an SES identity being deleted via the "DeleteIdentity" event. This may be an indicator of an adversary removing the account that carried out suspicious or malicious activities
Techniques: T1070
Author: Nasreddine Bencherchali (Nextron Systems) · 2023-02-16 · logsource: product=windows category=file_delete · 270185ff-5f50-4d6d-a27f-24c3b8c9fef8
Detects the deletion of tomcat WebServer logs which may indicate an attempt to destroy forensic evidence
Techniques: T1070
Author: Leo Tsaousis (@laripping) · 2024-03-26 · logsource: product=kubernetes category=application service=audit · 3132570d-cab2-4561-9ea6-1743644b2290
Detects when events are deleted in Kubernetes. An adversary may delete Kubernetes events in an attempt to evade detection.
Techniques: T1070
Author: Tim Rauch (Nextron Systems), Nasreddine Bencherchali (Nextron Systems) · 2022-09-16 (modified 2023-02-15) · logsource: product=windows category=file_delete · 3eb8c339-a765-48cc-a150-4364c04652bf
Detects the deletion of IIS WebServer access logs which may indicate an attempt to destroy forensic evidence
Techniques: T1070
Author: Nasreddine Bencherchali (Nextron Systems) · 2023-02-13 (modified 2025-10-07) · logsource: product=windows category=process_creation · 4931188c-178e-4ee7-a348-39e8a7a56821
Detect filter driver unloading activity via fltmc.exe
Author: Kirill Kiryanov, oscd.community · 2019-10-23 (modified 2023-02-13) · logsource: product=windows category=process_creation · 4d7cda18-1b12-4e52-b45c-d28653210df8
Detects possible Sysmon filter driver unloaded via fltmc.exe
Author: Nasreddine Bencherchali (Nextron Systems) · 2023-02-15 · logsource: product=windows category=file_delete · 63c779ba-f638-40a0-a593-ddd45e8b1ddc
Detects the deletion of the event log files which may indicate an attempt to destroy forensic evidence
Techniques: T1070
Author: Tuan Le (NCSGroup), Nasreddine Bencherchali (Nextron Systems) · 2023-03-09 · logsource: product=linux category=process_creation · 95d61234-7f56-465c-6f2d-b562c6fedbc4
Detects linux package removal using builtin tools such as "yum", "apt", "apt-get" or "dpkg".
Techniques: T1070
Author: Nasreddine Bencherchali (Nextron Systems) · 2022-07-17 (modified 2023-09-18) · logsource: product=windows category=image_load · 9e9a9002-56c4-40fd-9eff-e4b09bfa5f6c
Detects when a system process (i.e. located in system32, syswow64, etc.) loads a DLL from a suspicious location or a location with permissive permissions such as "C:\Users\Public"
Techniques: T1070
Author: @neu5ron, Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community · 2019-03-22 (modified 2022-06-28) · logsource: product=windows category=process_creation · a238b5d0-ce2d-4414-a676-7a531b3d13d6
Detects command line activity that tries to clear or disable any ETW trace log which could be a sign of logging evasion.
Techniques: T1070T1685
Author: Nasreddine Bencherchali (Nextron Systems) · 2022-10-26 (modified 2022-12-30) · logsource: product=windows category=file_delete · a55349d8-9588-4c5a-8e3b-1925fe2a4ffe
Detects the deletion of the Exchange PowerShell cmdlet History logs which may indicate an attempt to destroy forensic evidence
Techniques: T1070

All 20 rules on the technique page →

T1106 Native API exploitation technique

Sigma rules tagged attack.t1106 (14)

Author: Nasreddine Bencherchali (Nextron Systems), Nikita Nazarov, oscd.community · 2020-10-06 (modified 2026-04-29) · logsource: product=windows category=ps_script · 03d83090-8cba-44a0-b02f-0b756a050306
Detects usage of WinAPI functions in PowerShell scripts. It may indicate attempts to perform actions such as process injection, token stealing, or other malicious activities that leverage Windows API calls. These techniques are commonly used to evade traditional file-based detections by loading and executing code directly in memory.
Author: Christian Burkard (Nextron Systems) · 2021-08-04 (modified 2023-11-28) · logsource: product=windows category=process_access · 09706624-b7f6-455d-9d02-adee024cee1d
Detects a typical pattern of a CobaltStrike BOF which inject into other processes
Techniques: T1106T1685
Author: Nikita Nazarov, oscd.community, Nasreddine Bencherchali (Nextron Systems) · 2023-07-21 · logsource: product=windows category=ps_script · 19d65a1c-8540-4140-8062-8eb00db0bba5
Detects calls to WinAPI libraries from PowerShell scripts. Attackers can often leverage these APIs to avoid detection based on typical PowerShell function calls. Use this rule as a basis to hunt for interesting scripts.
Techniques: T1059.001T1106
Author: Christian Burkard (Nextron Systems), Tim Shelton (FP) · 2021-07-28 (modified 2023-12-13) · logsource: product=windows category=process_access · 3f3f3506-1895-401b-9cc3-e86b16e630d0
Detects potential calls to NtOpenProcess directly from NTDLL.
Techniques: T1106
Author: Markus Neis · 2017-11-06 (modified 2021-11-27) · logsource: product=windows category=pipe_created · 739915e4-1e70-4778-8b8a-17db02f66db1
Detects a named pipe used by Turla group samples
Techniques: T1106
Author: Rafal Piasecki · 2022-08-10 (modified 2026-03-30) · logsource: product=linux service=auditd · 808146b2-9332-4d78-9416-d7e47012d83d
detects BPFDoor .lock and .pid files access in temporary file storage facility
Techniques: T1106T1059
Author: Swachchhanda Shrawan Poudel · 2023-12-04 · logsource: product=windows category=ps_script · 851fd622-b675-4d26-b803-14bc7baa517a
Detects scriptblock text keywords indicative of potential usge of the tool WinPwn. A tool for Windows and Active Directory reconnaissance and exploitation.
Author: Alexander Rausch · 2020-06-24 (modified 2023-03-01) · logsource: product=windows category=process_creation · 95022b85-ff2a-49fa-939a-d7b8f56eeb9b
Detects actions caused by the RedMimicry Winnti playbook a automated breach emulations utility
Author: Nikita Nazarov, oscd.community, Nasreddine Bencherchali (Nextron Systems) · 2023-07-21 · logsource: product=windows category=ps_script · 9f22ccd5-a435-453b-af96-bf99cbb594d4
Detects calls to WinAPI functions from PowerShell scripts. Attackers can often leverage these APIs to avoid detection based on typical PowerShell function calls. Use this rule as a basis to hunt for interesting scripts.
Techniques: T1059.001T1106
Author: Bhabesh Raj (rule), @thefLinkk · 2022-06-27 (modified 2023-11-28) · logsource: product=windows category=process_access · b1bd3a59-c1fd-4860-9f40-4dd161a7d1f5
Detects HandleKatz opening LSASS to duplicate its handle to later dump the memory without opening any new handles
Techniques: T1106T1003.001
Author: Beyu Denis, oscd.community, Nasreddine Bencherchali (Nextron Systems) · 2019-10-26 (modified 2024-04-22) · logsource: product=windows category=process_creation · b5c7395f-e501-4a08-94d4-57fe7a9da9d2
Detects usage of "cdb.exe" to launch arbitrary processes or commands from a debugger script file
Techniques: T1106T1218T1127
Author: Nasreddine Bencherchali (Nextron Systems) · 2022-09-06 (modified 2025-03-06) · logsource: product=windows category=process_creation · ba3f5c1b-6272-4119-9dbd-0bc8d21c2702
Detects the use of WinAPI Functions via the commandline. As seen used by threat actors via the tool winapiexec
Techniques: T1106
Author: Swachchhanda Shrawan Poudel · 2023-12-04 · logsource: product=windows category=process_creation · d557dc06-62e8-4468-a8e8-7984124908ce
Detects commandline keywords indicative of potential usge of the tool WinPwn. A tool for Windows and Active Directory reconnaissance and exploitation.
Author: Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems) · 2021-07-17 (modified 2023-02-21) · logsource: product=windows category=process_creation · e32f92d1-523e-49c3-9374-bdb13b46a3ba
Detects suspicious mshta process execution patterns
Techniques: T1106

T1496 Resource Hijacking primary impact

Sigma rules tagged attack.t1496 (13)

Author: Austin Songer @austinsonger · 2021-08-07 (modified 2022-08-23) · logsource: product=azure service=activitylogs · 08d6ac24-c927-4469-b3b7-2e422d6e3c43
Identifies when a Azure Kubernetes network policy is modified or deleted.
Techniques: T1485T1496T1489
Author: Austin Songer @austinsonger · 2021-08-07 (modified 2022-08-23) · logsource: product=azure service=activitylogs · 12d027c3-b48c-4d9d-8bb6-a732200034b2
Identifies when a service account is modified or deleted.
Author: Austin Songer @austinsonger · 2021-08-07 (modified 2022-08-23) · logsource: product=azure service=activitylogs · 25cb259b-bbdc-4b87-98b7-90d7c72f8743
Detects the creation or patching of potential malicious RoleBinding/ClusterRoleBinding.
Techniques: T1485T1496T1489
Author: Florian Roth (Nextron Systems) · 2021-10-26 (modified 2023-02-13) · logsource: product=windows category=process_creation · 66c3b204-9f88-4d0a-a7f7-8a57d521ca55
Detects command line parameters or strings often used by crypto miners
Techniques: T1496
Author: Austin Songer @austinsonger · 2021-08-07 (modified 2022-08-23) · logsource: product=azure service=activitylogs · 7ee0b4aa-d8d4-4088-b661-20efdf41a04c
Identifies when a Kubernetes account access a sensitive objects such as configmaps or secrets.
Techniques: T1485T1496T1489
Author: Austin Songer @austinsonger · 2021-08-07 (modified 2022-08-23) · logsource: product=azure service=activitylogs · 818fee0c-e0ec-4e45-824e-83e4817b0887
Identifies when ClusterRoles/Roles are being modified or deleted.
Techniques: T1485T1496T1489
Author: Florian Roth (Nextron Systems) · 2021-10-26 (modified 2022-12-25) · logsource: product=linux category=process_creation · 9069ea3c-b213-4c52-be13-86506a227ab1
Detects command line parameters or strings often used by crypto miners
Techniques: T1496
Author: Austin Songer @austinsonger · 2021-08-07 (modified 2022-08-23) · logsource: product=azure service=activitylogs · 93e0ef48-37c8-49ed-a02c-038aab23628e
Detects when a Container Registry is created or deleted.
Techniques: T1485T1496T1489
Author: Austin Songer @austinsonger · 2021-08-07 (modified 2022-08-23) · logsource: product=azure service=activitylogs · 9541f321-7cba-4b43-80fc-fbd1fb922808
Detects when a Azure Kubernetes Cluster is created or deleted.
Techniques: T1485T1496T1489
Author: Florian Roth (Nextron Systems) · 2021-10-26 · logsource: product=linux category=network_connection · a46c93b7-55ed-4d27-a41b-c259456c4746
Detects process connections to a Monero crypto mining pool
Techniques: T1496
Author: Florian Roth (Nextron Systems) · 2021-10-24 · logsource: category=dns · b593fd50-7335-4682-a36c-4edcb68e4641
Detects suspicious DNS queries to Monero mining pools
Techniques: T1496T1567
Author: Saw Winn Naung, Azure-Sentinel, @neu5ron · 2021-08-19 (modified 2022-07-07) · logsource: product=zeek service=dns · bf74135c-18e8-4a72-a926-0e4f47888c19
Identifies clients that may be performing DNS lookups associated with common currency mining pools.
Techniques: T1569.002T1496
Author: Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems) · 2021-10-26 (modified 2026-07-24) · logsource: product=windows category=network_connection · fa5b1358-b040-4403-9868-15f7d9ab6329
Detects initiated network connections to crypto mining pools. It indicates that the system is likely infected with a crypto miner malware or is being used for crypto mining.
Techniques: T1496

T1498 Network Denial of Service secondary impact

Sigma rules tagged attack.t1498 (3)

Author: Leo Tsaousis (@laripping) · 2024-03-26 · logsource: product=kubernetes category=application service=audit · 40967487-139b-4811-81d9-c9767a92aa5a
Detects the removal of a deployment from a Kubernetes cluster. This could indicate disruptive activity aiming to impact business operations.
Techniques: T1498
Author: Security Onion Solutions · 2024-03-08 · logsource: product=opencanary category=application · 7cded4b3-f09e-405a-b96f-24248433ba44
Detects instances where an NTP service on an OpenCanary node has had a NTP monlist request.
Techniques: T1498
Author: Florian Roth (Nextron Systems) · 2022-02-25 (modified 2023-02-08) · logsource: product=windows category=process_creation · 999e8307-a775-4d5f-addc-4855632335be
Detects command line patterns used by BlackByte ransomware in different operations

Sigma rules tagged with this CVE directly

1 rule carries cve.2023-1389.

Author: Nasreddine Bencherchali (Nextron Systems), Rohit Jain · 2024-06-25 · logsource: category=proxy · 6c7defa9-69f8-4c34-b815-41fce3931754
Detects potential exploitation attempt of CVE-2023-1389 an Unauthenticated Command Injection in TP-Link Archer AX21.
Techniques: T1190
CVE tags: CVE-2023-1389