VendorsTP-Linkarcher_ax21_firmwareall versions
Vulnerabilities

TP-Link ARCHER AX21

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2023-27359
TP-Link AX1800 hotplugd Firewall Rule Race Condition Vulnerability
Published 2024-05-03 · Analyzed
9.8EPSS 0.012
CVE-2023-31710
TP-Link Archer AX21(US)_V3_1.1.4 Build 20230219 and AX21(US)_V3.6_1.1.4 Build 20230219 are vulnerable to Buffer Overflow.
Published 2023-08-01 · Modified
9.8EPSS 0.007
CVE-2023-1389
TP-Link Archer AX21 (AX1800) firmware versions before 1.1.4 Build 20230219 contained a command injection vulnerability in the country form of the /cgi-bin/luci;stok=/locale endpoint on the web management interface. Specifically, the country parameter of the write operation was not sanitized before being used in a call to popen(), allowing an unauthenticated attacker to inject commands, which would be run as root, with a simple POST request.
Published 2023-03-15 · Analyzed
8.8KEV1 PoCEPSS 1.000
CVE-2023-27332
TP-Link Archer AX21 tdpServer Logging Stack-based Buffer Overflow Remote Code Execution Vulnerability
Published 2024-05-03 · Analyzed
8.8EPSS 0.007
CVE-2023-27346
TP-Link AX1800 Firmware Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability
Published 2024-05-03 · Analyzed
8.8EPSS 0.007
CVE-2023-27333
TP-Link Archer AX21 tmpServer Command 0x422 Stack-based Buffer Overflow Remote Code Execution Vulnerability
Published 2024-05-03 · Analyzed
6.8EPSS 0.007