Loading HuntDB...

GHSA-h49r-m2rg-6pgf

GitHub Security Advisory

⚠ Unreviewed HIGH Has CVE

Advisory Details

TP-Link Archer AX21 (AX1800) firmware versions before 1.1.4 Build 20230219 contained a command injection vulnerability in the country form of the /cgi-bin/luci;stok=/locale endpoint on the web management interface. Specifically, the country parameter of the write operation was not sanitized before being used in a call to popen(), allowing an unauthenticated attacker to inject commands, which would be run as root, with a simple POST request.

Related CVEs

Key Information

GHSA ID
GHSA-h49r-m2rg-6pgf
Published
March 16, 2023 12:32 AM
Last Modified
March 21, 2023 9:30 PM
CVSS Score
7.5 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: June 12, 2025 6:24 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.