{"cveID":"CVE-2023-1389","vendorProject":"TP-Link","product":"Archer AX21","vulnerabilityName":"TP-Link Archer AX-21 Command Injection Vulnerability","dateAdded":"2023-05-01","shortDescription":"TP-Link Archer AX-21 contains a command injection vulnerability that allows for remote code execution.","requiredAction":"Apply updates per vendor instructions.","dueDate":"2023-05-22","knownRansomwareCampaignUse":"Unknown","notes":"https://www.tp-link.com/us/support/download/archer-ax21/v3/#Firmware;  https://nvd.nist.gov/vuln/detail/CVE-2023-1389","cwes":["CWE-77"],"year":2023,"state":"mapped","stale_reasons":[],"mappings":[{"domain":"enterprise","cve":"CVE-2023-1389","technique":"T1106","technique_name_at_mapping":"Native API","mapping_type":"exploitation_technique","capability_group":"command_injection","comments":"CVE-2023-1389 is a command injection vulnerability in one of the API components within the TP-Link Archer router’s web management interface. Public reports have reported that multiple botnet malware under the Mirai variants, including Condi, are targeting these vulnerable devices. \n","references":["https://www.fortinet.com/blog/threat-research/botnets-continue-exploiting-cve-2023-1389-for-wide-scale-spread","https://cybersecuritynews.com/hackers-exploiting-tp-link/","https://www.bleepingcomputer.com/news/security/multiple-botnets-exploiting-one-year-old-tp-link-flaw-to-hack-routers/"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2023-1389","technique":"T1041","technique_name_at_mapping":"Exfiltration Over C2 Channel","mapping_type":"secondary_impact","capability_group":"command_injection","comments":"CVE-2023-1389 is a command injection vulnerability in one of the API components within the TP-Link Archer router’s web management interface. Public reports have reported that multiple botnet malware under the Mirai variants, including Condi, are targeting these vulnerable devices. \n","references":["https://thehackernews.com/2023/06/new-condi-malware-hijacking-tp-link-wi.html","https://cybersecuritynews.com/hackers-exploiting-tp-link/","https://www.bleepingcomputer.com/news/security/multiple-botnets-exploiting-one-year-old-tp-link-flaw-to-hack-routers/"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2023-1389","technique":"T1070","technique_name_at_mapping":"Indicator Removal","mapping_type":"secondary_impact","capability_group":"command_injection","comments":"CVE-2023-1389 is a command injection vulnerability in one of the API components within the TP-Link Archer router’s web management interface. Public reports have reported that multiple botnet malware under the Mirai variants, including Condi, are targeting these vulnerable devices. \n","references":["https://thehackernews.com/2023/06/new-condi-malware-hijacking-tp-link-wi.html","https://cybersecuritynews.com/hackers-exploiting-tp-link/","https://www.bleepingcomputer.com/news/security/multiple-botnets-exploiting-one-year-old-tp-link-flaw-to-hack-routers/"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2023-1389","technique":"T1496","technique_name_at_mapping":"Resource Hijacking","mapping_type":"primary_impact","capability_group":"command_injection","comments":"CVE-2023-1389 is a command injection vulnerability in one of the API components within the TP-Link Archer router’s web management interface. Public reports have reported that multiple botnet malware under the Mirai variants, including Condi, are targeting these vulnerable devices. \n","references":["https://thehackernews.com/2023/06/new-condi-malware-hijacking-tp-link-wi.html","https://cybersecuritynews.com/hackers-exploiting-tp-link/","https://www.bleepingcomputer.com/news/security/multiple-botnets-exploiting-one-year-old-tp-link-flaw-to-hack-routers/"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2023-1389","technique":"T1498","technique_name_at_mapping":"Network Denial of Service","mapping_type":"secondary_impact","capability_group":"command_injection","comments":"CVE-2023-1389 is a command injection vulnerability in one of the API components within the TP-Link Archer router’s web management interface. Public reports have reported that multiple botnet malware under the Mirai variants, including Condi, are targeting these vulnerable devices. \n","references":["https://thehackernews.com/2023/06/new-condi-malware-hijacking-tp-link-wi.html","https://cybersecuritynews.com/hackers-exploiting-tp-link/","https://www.bleepingcomputer.com/news/security/multiple-botnets-exploiting-one-year-old-tp-link-flaw-to-hack-routers/"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"}],"techniques":[{"id":"T1041","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Exfiltration Over C2 Channel","name_at_mapping":"Exfiltration Over C2 Channel","renamed":false,"revoked_by":null,"mapping_types":["secondary_impact"],"sigma_rule_count":5,"has_detection_strategy":true},{"id":"T1070","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Indicator Removal","name_at_mapping":"Indicator Removal","renamed":false,"revoked_by":null,"mapping_types":["secondary_impact"],"sigma_rule_count":20,"has_detection_strategy":true},{"id":"T1106","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Native API","name_at_mapping":"Native API","renamed":false,"revoked_by":null,"mapping_types":["exploitation_technique"],"sigma_rule_count":14,"has_detection_strategy":true},{"id":"T1496","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Resource Hijacking","name_at_mapping":"Resource Hijacking","renamed":false,"revoked_by":null,"mapping_types":["primary_impact"],"sigma_rule_count":13,"has_detection_strategy":true},{"id":"T1498","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Network Denial of Service","name_at_mapping":"Network Denial of Service","renamed":false,"revoked_by":null,"mapping_types":["secondary_impact"],"sigma_rule_count":3,"has_detection_strategy":true}],"mapping_types":["exploitation_technique","primary_impact","secondary_impact"],"has_exploitation_technique":true,"mapping_attack_versions":["16.1"],"mapping_domains":["enterprise"],"sigma_coverage":"full","sigma_rules_tagged_cve":["6c7defa9-69f8-4c34-b815-41fce3931754"],"added_after_mapping_snapshot":false,"_source":"kevmap","_built":"2026-08-24 19:45 UTC","_attack_version":"19.2"}