PatchSiren

PatchSiren cyber security CVE debrief

CVE-2023-1389 TP-Link CVE debrief

CVE-2023-1389 is a TP-Link Archer AX21 command injection vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2023-05-01. Because it is KEV-listed, defenders should treat it as urgent and apply vendor updates as soon as possible, following TP-Link guidance referenced by CISA.

Vendor
TP-Link
Product
Archer AX21
CVSS
Unknown
CISA KEV
Listed
Original CVE published
2023-05-01
Original CVE updated
2026-09-27
Advisory published
2026-09-27
Advisory updated
2026-09-27

Who should care

Organizations that use or manage TP-Link Archer AX21 routers, including IT teams, network administrators, MSPs, and anyone responsible for edge/network devices.

Technical summary

The available official corpus identifies the issue as a command injection vulnerability in the TP-Link Archer AX21. CISA lists it as a known exploited vulnerability and directs affected users to apply updates per vendor instructions. No CVSS score or version-specific technical breakdown was provided in the supplied sources.

Defensive priority

Urgent. KEV-listed vulnerabilities are high-priority remediation items, and CISA set a due date of 2023-05-22 for this entry.

Recommended defensive actions

  • Inventory all TP-Link Archer AX21 devices in your environment.
  • Check device firmware against TP-Link's support and firmware guidance referenced by CISA.
  • Apply the latest vendor-provided firmware updates on affected devices.
  • If immediate patching is not possible, reduce exposure by limiting administrative access to the router and placing it behind trusted management controls.
  • Monitor affected devices for unexpected configuration changes or abnormal behavior.
  • Track remediation against the CISA KEV due date and verify completion.

Evidence notes

CISA's Known Exploited Vulnerabilities catalog identifies CVE-2023-1389 as a TP-Link Archer AX21 command injection vulnerability, with dateAdded 2023-05-01 and dueDate 2023-05-22. The supplied notes point to TP-Link firmware resources and the NVD CVE detail page; however, no additional version scope or CVSS data was included in the corpus.

Sources and references

Verified primary and authoritative sources

  • CVE-2023-1389 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2023-1389

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2023-1389 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2023-1389

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

  • CISA Known Exploited Vulnerabilities catalog

    Publisher, destination, and source semantics verified

    URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog

    Cybersecurity and Infrastructure Security Agency - Official CISA catalog of vulnerabilities known to be exploited in the wild.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json

    cisa_kev

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.