CVE-2023-1389Active Exploitation(tp-link / archer_ax21)

HIGHCVSS 8.8 · HIGHCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for tp-link archer_ax21 systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

TP-Link Archer AX21 (AX1800) firmware versions before 1.1.4 Build 20230219 contained a command injection vulnerability in the country form of the /cgi-bin/luci;stok=/locale endpoint on the web management interface. Specifically, the country parameter of the write operation was not sanitized before being used in a call to popen(), allowing an unauthenticated attacker to inject commands, which would be run as root, with a simple POST request.

7.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2023-05-22. Apply updates per vendor instructions.

Weakness type (CWE)
CWE-77

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • archer_ax21
  • archer_ax21_firmware

Threat summary

  • Active exploitation appears in 13 classified signals
  • Public PoC and exploit tooling are both present
  • 17 mentions across 17 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 13 signals
  • Exploit tool or code specified in 7 signals
  • PoC mentioned or linked in 4 signals
  • Technical details provided in 5 signals
  • Peaked 16d ago at 1 mentions (2026-02-19); latest day: 1
  • 17 total mentions across 17 days

Affected systems

Vendors
Products
archer_ax21archer_ax21_firmware

1 version affected across 2 products

Deep dive

Activity timeline17 mentions / 17d
00111Mentions · 2026-02-19: 1Mentions · 2026-02-22: 1Mentions · 2026-04-24: 1Mentions · 2026-04-26: 1Mentions · 2026-04-28: 1Mentions · 2026-04-30: 1Mentions · 2026-05-01: 1Mentions · 2026-05-08: 1Mentions · 2026-05-13: 1Mentions · 2026-05-14: 1Mentions · 2026-06-08: 1Mentions · 2026-06-24: 1Mentions · 2026-07-02: 1Mentions · 2026-08-20: 1Mentions · 2026-10-02: 1Mentions · 2026-10-05: 1Mentions · 2026-10-06: 1PoC Mentioned / Linked · 2026-04-28: 1PoC Mentioned / Linked · 2026-05-01: 1PoC Mentioned / Linked · 2026-05-13: 1PoC Mentioned / Linked · 2026-06-08: 1Exploit Tool / Code · 2026-02-19: 1Exploit Tool / Code · 2026-02-22: 1Exploit Tool / Code · 2026-04-28: 1Exploit Tool / Code · 2026-05-08: 1Exploit Tool / Code · 2026-05-13: 1Exploit Tool / Code · 2026-06-24: 1Exploit Tool / Code · 2026-08-20: 1Active Exploitation · 2026-02-19: 1Active Exploitation · 2026-02-22: 1Active Exploitation · 2026-04-24: 1Active Exploitation · 2026-04-26: 1Active Exploitation · 2026-04-28: 1Active Exploitation · 2026-04-30: 1Active Exploitation · 2026-05-01: 1Active Exploitation · 2026-05-13: 1Active Exploitation · 2026-05-14: 1Active Exploitation · 2026-06-08: 1Active Exploitation · 2026-06-24: 1Active Exploitation · 2026-07-02: 1Active Exploitation · 2026-08-20: 1Technical Details · 2026-02-22: 1Technical Details · 2026-04-24: 1Technical Details · 2026-04-26: 1Technical Details · 2026-05-13: 1Technical Details · 2026-06-08: 102-1902-2204-2404-2604-2804-3005-0105-0805-1305-1406-0806-2407-0208-2010-0210-0510-06
Signal classification2 categories
Active Exploitation
1178.6%
Exploit
321.4%
Referenced assets37 URLs
By indicator
Classification over time
DateTotalLabels
2026-02-191
Active Exploitation1
2026-02-221
Active Exploitation1
2026-04-241
Active Exploitation1
2026-04-261
Active Exploitation1
2026-04-281
Active Exploitation1
2026-04-301
Active Exploitation1
2026-05-011
Active Exploitation1
2026-05-081
Exploit1
2026-05-131
Exploit1
2026-05-141
Active Exploitation1
2026-06-081
Active Exploitation1
2026-06-241
Active Exploitation1
2026-07-021
Active Exploitation1
2026-08-201
Exploit1
Full discourse17 posts
  • sicehice@sicehice
    Active Exploitation

    #RCE attempt targeting TP-Link Archer AX21 (CVE-2023-1389) 2026-04-28 09:34:28 UTC Source IP: 137.184.20.87 🇺🇸 IOCs: hxxp://78.11.101.78/Beastmode.sh hxxp://78.11.10.78/Beastmode.sh 78.11.101.78 🇵🇱 78.11.10.7 🇵🇱 77.111.101.78 🇧🇷 77.11.101.78 🇩🇪 78.11.10.78 🇵🇱 https://t.co/aGn11b2OKZ

    Post summary

    The post documents an active remote code execution attempt against TP‑Link Archer AX21, providing attack IPs and a malicious script link to demonstrate the exploit.

    02031609
    1.7K followersView on X
  • sicehice@sicehice
    Active Exploitation

    #RCE attempt targeting TP-Link Archer AX21 to distribute #Mirai (CVE-2023-1389) 2026-04-26 11:46:16 UTC Source IP: 176.65.139.140 🇩🇪 IOCs: hxxp://83.168.110.191/cat.sh 83.168.110.191 🇵🇱 (C2) dca40f08cc93bc2fba8e3f5fec18593f https://t.co/iVxkslM5Nh

    Post summary

    The tweet reports an ongoing remote code execution attack against TP‑Link Archer AX21 using CVE‑2023‑1389 to deploy the Mirai botnet, accompanied by relevant IOCs.

    01021353
    1.7K followersView on X
  • sicehice@sicehice
    Exploit

    #RCE attempt targeting TP-Link Archer AX21 to distribute #Mirai (CVE-2023-1389) 2026-08-20 06:47:35 UTC Source IP: 77.239.124.108 🇳🇱 POST /cgi-bin/luci/;stok=/locale?form=country IOCs: hxxp://77.239.124.108/atomic/atomic.sh 77.239.124.108 🇳🇱 4569e49b75a4e59bb3b967aa250a37b6 https://t.co/J9wFHmBZR8

    Post summary

    An active RCE attempt was observed on a TP‑Link Archer AX21 using CVE‑2023‑1389, with evidence of a malicious shell script and Mirai distribution.

    11010401
    1.7K followersView on X
  • sicehice@sicehice
    Active Exploitation

    #RCE attempt targeting TP-Link Archer AX21 to distribute #Mirai (CVE-2023-1389) 2026-07-02 20:49:18 UTC Source IP: 94.154.43.158 🇹🇷 POST /cgi-bin/luci/;stok=/locale?form=country IOCs: hxxp://94.154.43.158/ghost.sh 94.154.43.158 🇹🇷 ae095e417dd60f8515bbbfc561f39ffb https://t.co/XOyS1b3cbW

    Post summary

    An attacker used CVE-2023-1389 to target a TP‑Link Archer AX21 router and serve a Mirai payload in the wild.

    01011299
    1.7K followersView on X
  • sicehice@sicehice
    Active Exploitation

    #RCE attempt targeting TP-Link Archer AX21 (CVE-2023-1389) 2026-04-24 19:35:38 UTC Source IP: 45.135.193.131 🇩🇪 POST /cgi-bin/luci;stok=/locale?form=country IOCs: aps.voltpanel[.]cloud hxxps://aps.voltpanel.cloud/install.sh 142.248.80.139 🇺🇸 45.153.34.194 🇳🇱 (C2) https://t.co/gqlFLPqt3G

    Post summary

    An attacker executed an RCE attempt against TP‑Link Archer AX21 using CVE‑2023‑1389, with associated C2 IPs and a malicious install script, confirming ongoing exploitation activity.

    10011386
    1.7K followersView on X
  • sicehice@sicehice
    Active Exploitation

    #RCE attempt targeting TP-Link Archer AX21 to distribute #Mirai (CVE-2023-1389) 2026-05-14 19:50:07 UTC Source IP: 176.65.139.165 🇩🇪 POST /cgi-bin/luci/;stok=/locale?form=country IOCs: hxxp://156.238.242.196/linux.sh 156.238.242.196 🇸🇨 cfc6846c015cff381e97428648603ba1 https://t.co/5HhIShU6BX

    Post summary

    This tweet reports a real-world exploitation attempt against TP‑Link Archer AX21 devices using CVE‑2023‑1389 to deliver Mirai, providing the source IP, attack vector, and associated malicious IOCs, but it does not share PoC code or patch details.

    00011373
    1.7K followersView on X
  • RST Cloud@rst_cloud
    Active Exploitation

    #threatreport #MediumCompleteness To Cache A Predator: ILOVEPOOP Toolkit Discovery, Global Traffic & Honeypot Observations Exploiting React2Shell (CVE-2025-55182) | 06-02-2026 Source: https://main.whoisxmlapi.com/blog/to-cache-a-predator-ilovepoop-toolkit-react2shell-cve-2025-55182 Key details below ↓ 💀Threats: Ilovepoop_tool, React2shell_vuln, Mirai, Kimwolf, 🎯Victims: Organizations using next.js or react server components, Industrial control systems 🏭Industry: Ics, Iot, E-commerce, Education, Media, Energy, Entertainment, Financial, Retail, Government, Telco, Healthcare 🌐Geo: Brazil, Poland, India, Asia, Bulgarian, Vietnam, Netherland, Singapore, Egypt, Hong kong, Russia, Canada, Serbia, China, Australia, Bulgaria, Philippines, Malaysia, Taiwan, United kingdom, Japan, Laos, Netherlands, Latin america, Mexico, Germany, Korea, France 🔓CVEs: CVE-2025-55182 \[[Vulners](https://vulners.com/cve/CVE-2025-55182)] - CVSS V3.1: *10.0*, - Vulners: Exploitation: True Soft: - facebook react (19.0.0, 19.1.0, 19.1.1, 19.2.0) CVE-2017-9841 \[[Vulners](https://vulners.com/cve/CVE-2017-9841)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - phpunit_project phpunit (le4.8.27, <5.6.3) CVE-2023-1389 \[[Vulners](https://vulners.com/cve/CVE-2023-1389)] - CVSS V3.1: *8.8*, - Vulners: Exploitation: True Soft: - tp-link archer_ax21_firmware (<1.1.4) 🤖LLM extracted TTPs:` T1021, T1046, T1078, T1110, T1133, T1190, T1211, T1590, T1592.004, T1595, ... 🧨IOCs: - File: 5 - IP: 30 💽Software: Firefox, Linux, PHPUnit, Android 🔢Algorithms: deflate, gzip, exhibit 📜Programming Languages: php, javascript 💻Platforms: apple, intel #threatreport: The report on React2Shell (CVE-2025-55182) reveals a coordinated exploitation campaign characterized by the use of the ILOVEPOOP toolkit, observed through global telemetry and honeypot data. Following the public disclosure of the vulnerability in December 2025, exploit attempts were recorded by Niihama sensors within just 20 hours, highlighting the promptness of hostile actors in leveraging this security flaw. Key findings indicate a high centralization of attacker infrastructure around two nodes hosted in the Netherlands, which accounted for a significant portion of the exploit traffic. The ILOVEPOOP toolkit, identified as a single-operator solution, was active across nine nodes and generated a total of 672 exploit attempts with uniform exploit headers and specific patterns signaling the React2Shell methodology. For instance, requests from the toolkit consistently featured multipart data types and peculiar headers like "Next-Action: x" and user-agent strings that suggest a coordinated effort to exploit various Next.js components. Extended scanning activities were noted from January 5th to February 6th, 2026, with a total of 894 requests originating from 43 unique IP addresses. This persistent probing was directed at specific Next.js routes, including bulk scanning of JavaScript bundles for sensitive information like credentials and API keys. The outreach was diverse, targeting thousands of organizations across several regions, particularly in the U.S., with substantial traffic aiming for Next.js vulnerabilities. One noteworthy aspect of the campaign was a cross-protocol attack where a React2Shell exploit attempt was sent to a POP3 daemon, showcasing a multi-protocol delivery mechanism that could evade standard security measures. This manipulation involved leveraging prototype pollution to achieve remote code execution via the React Server Components framework. Such behavior underscores the evolving strategies of threat actors to exploit multiple protocols simultaneously, indicating a potentially advanced and adaptable threat landscape. Two specific IP addresses from the attack infrastructure, 87.121.84.24 and 193.142.147.209, exhibited different behaviors; the former was confirmed to actively exploit React2Shell while the latter showed a mix of probing consistent with IoT botnet activity. The campaign's high signal of scanning activity indicates not only immediate exploitative actions but also a broader reconnaissance for potential vulnerabilities across various services and infrastructures. The data underscores a need for heightened awareness and preemptive security measures against the React2Shell threat and similar toolkit behaviors, particularly for organizations using Next.js and involved in web application development. The evolving nature of the attack patterns necessitates continuous monitoring and adaptation of cybersecurity defenses, especially in light of the emerging multi-protocol exploitation strategies evidenced in this campaign.

    Post summary

    The report documents a coordinated, real‑world exploitation campaign against React2Shell (CVE‑2025‑55182) using the ILOVEPOOP toolkit, with rapid post‑disclosure activity and detailed technical indicators of attack.

    00020183
    587 followersView on X
  • DFIR Radar@DFIR_Radar

    Cling botnet exploits CVE-2021-35394 (CVSS 9.8) in Realtek Jungle SDK, abusing public STUN infrastructure to disguise C2 traffic as legitimate NAT-traversal activity across routers, DVRs, and embedded Linux devices. Key details: - Exploitation of CVE-2021-35394 spiked around September 5, 2026, delivering Cling (also tracked as ClingSTUN by Fortinet). The botnet embeds hard-coded exploits for seven CVEs used in self-propagation: CVE-2014-8361 (Realtek), CVE-2016-20016 (MVPower), CVE-2023-26801 (LB-LINK), CVE-2023-41011 (China 🇨🇳 Mobile/FiberHome), CVE-2024-3721 (TBK DVR), CVE-2025-34037 (Linksys), and CVE-2026-87827 (KGUARD DVR). Initial access spans a much wider set including D-Link, Tenda, Ivanti Connect Secure (CVE-2023-46805, CVE-2024-21887), TP-Link CVE-2023-1389, AVTECH CVE-2024-7029, and others. - The C2 mechanism is the standout: Cling sends STUN Binding Requests to 13 hard-coded servers every five seconds, using an all-zero transaction ID (a deliberate protocol deviation). It then sends custom UDP registration datagrams containing mapped ports and infection-source tags like realtek.selfrep or selfrep.router. Operator commands arrive embedded in the STUN transaction ID field. The controlled server 145.249.115[.]184 returns all-zero transaction IDs rather than echoing the request, the tell that it is operator-controlled. More striking: observed command packets originate from 74.125.250[.]129, an IP resolving to stun.l[.]google[.]com, making malicious replies visually indistinguishable from Google STUN responses. - Persistence is layered: the binary copies itself to /root/.cling and /usr/local/bin/.cling, then appends both paths to /etc/inittab, /etc/init.d/rcS, and /etc/rc.d/rc.boot for SysV and BusyBox init survival. A secondary persistence method replaces the legitimate wget binary with the malware, relocating the original, so any legitimate process invoking wget executes the bot instead. Single-instance enforcement uses SO_REUSEADDR on port 33957. - Once established, Cling supports recursive scanning and worm-like spread, TCP tunnel spawn/stop, proxy launch/stop, and timed DoS floods. Observed flood targets include 112.151.157[.]222:8080, 192.170.240[.]137:53, and Minecraft servers at 23.81.40[.]193:25565 and 147.185.221[.]129:25565. Payloads are fetched via shell script downloaders for ARM, MIPS R3000, PowerPC, Intel 80386, and AMD X86-64, maximizing the range of vulnerable embedded hardware. Network defenders: hunt outbound UDP to port 3478 with zero-byte transaction IDs and flag UDP datagrams to public STUN servers that do not conform to RFC 5389 (non-random transaction IDs, oversized or non-standard payloads). On the host side, check for /root/.cling, /usr/local/bin/.cling, and modifications to /etc/inittab or rcS. Validate the wget binary hash against a known-good baseline: a replaced wget is a clean persistence indicator with no legitimate use case. Port 33957 bound with SO_REUSEADDR on a router or DVR is a direct Cling presence signal. Full IOC list is in the Nozomi Networks report. #DFIR_Radar

    10000186
    2.0K followersView on X
  • sicehice@sicehice
    Active Exploitation

    #RCE attempt targeting TP-Link Archer AX21 to distribute #Mirai (CVE-2023-1389) 2026-06-24 11:21:28 UTC Source IP: 176.65.139.158 🇩🇪 POST /cgi-bin/luci/;stok=/locale?form=country IOCs: hxxp://176.65.139.158/ghost.sh 176.65.139.158 🇩🇪 0859085d3ab968de9ccfb9a829ea19af https://t.co/eJmNAOnEWY

    Post summary

    The report details a live RCE attempt against TP‑Link Archer AX21 using CVE‑2023‑1389 to deploy Mirai, accompanied by a malicious script and source IP—demonstrating ongoing exploitation.

    01000328
    1.7K followersView on X
  • sicehice@sicehice
    Exploit

    #RCE attempt targeting TP-Link Archer AX21 to distribute #Mirai (CVE-2023-1389) 2026-05-12 14:33:43 UTC Source IP: 142.248.80.31 🇺🇸 IOCs: hxxp://142.248.80.144/lol.sh 142.248.80.144 🇺🇸 8ae5e4a4c875e45975faf989dbf83214 https://t.co/hBcgux6zty

    Post summary

    The post reports a live exploitation attempt against TP‑Link Archer AX21 using CVE‑2023‑1389, providing a likely PoC script aimed at distributing Mirai malware, indicating both an exploit and active malicious use.

    00001351
    1.7K followersView on X
  • sicehice@sicehice
    Exploit

    #RCE attempt targeting TP-Link Archer AX21 routers (CVE-2023-1389) 2026-05-08 11:11:17 UTC Source IP: 45.157.233.103 🇩🇪 IOCs: hxxp://45.157.233.103/phantom.sh 45.157.233.103 🇩🇪3b67ea25fe8336d31ff480af4c857615 https://t.co/J536UgdoFe

    Post summary

    An attempt to exploit CVE‑2023‑1389 on TP‑Link Archer AX21 routers was observed, with IOCs pointing to a shell script, but there is no evidence of successful exploitation or a publicly released exploit kit.

    00010403
    1.7K followersView on X
  • sicehice@sicehice
    Active Exploitation

    #RCE attempt targeting TP-Link Archer AX21 to distribute #Mirai #Gafgyt (CVE-2023-1389) #GuruITDDoS #HoneyPatte 2026-05-01 02:28:44 UTC Source IP: 62.171.169.207 🇫🇷 IOCs: 92.88.98.199 🇫🇷 hxxp://92.88.98.199/GuruITDDoS/RpcSecurity.x86_64 6a7a32cee9c2dcd46784a93edc339c0e https://t.co/CMcMP1elKr

    Post summary

    The post reports a live exploitation attempt of CVE‑2023‑1389 on TP‑Link Archer AX21, delivering Mirai/Gafgyt malware via a supplied binary link.

    00010324
    1.7K followersView on X
  • RST Cloud@rst_cloud

    #threatreport #LowCompleteness ClingSTUN Linux Backdoor Abuses Public STUN Infrastructure | 05-10-2026 Source: https://www.fortinet.com/blog/threat-research/clingstun-linux-backdoor-abuses-public-stun-infrastructure Key details below ↓ 💀Threats: Clingstun, 🎯Victims: Internet facing devices, Iot devices, Linux devices, Routers 🔓CVEs: CVE-2026-87827 \[[Vulners](https://vulners.com/cve/CVE-2026-87827)] - CVSS V3.1: *10.0*, - Vulners: Exploitation: True CVE-2024-10915 \[[Vulners](https://vulners.com/cve/CVE-2024-10915)] - CVSS V3.1: *8.1*, - Vulners: Exploitation: True Soft: - dlink dns-320_firmware (*) CVE-2024-3721 \[[Vulners](https://vulners.com/cve/CVE-2024-3721)] - CVSS V3.1: *6.3*, - Vulners: Exploitation: True CVE-2019-7256 \[[Vulners](https://vulners.com/cve/CVE-2019-7256)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - nortekcontrol linear_emerge_essential_firmware (le1.00-06) CVE-2016-20016 \[[Vulners](https://vulners.com/cve/CVE-2016-20016)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - mvpower tv-7104he_firmware (1.8.4_115215b9) CVE-2024-32292 \[[Vulners](https://vulners.com/cve/CVE-2024-32292)] - CVSS V3.1: *8.8*, - Vulners: Exploitation: Unknown Soft: - tenda w30e_firmware (1.0.1.25\(633\)) CVE-2021-35394 \[[Vulners](https://vulners.com/cve/CVE-2021-35394)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - realtek rtl819x_jungle_software_development_kit (le3.4.14b) CVE-2024-32281 \[[Vulners](https://vulners.com/cve/CVE-2024-32281)] - CVSS V3.1: *8.8*, - Vulners: Exploitation: Unknown Soft: - tenda ac7_firmware (15.03.06.44) CVE-2024-32314 \[[Vulners](https://vulners.com/cve/CVE-2024-32314)] - CVSS V3.1: *3.8*, - Vulners: Exploitation: Unknown Soft: - tenda ac500_firmware (2.0.1.9\(1307\)) CVE-2025-67038 \[[Vulners](https://vulners.com/cve/CVE-2025-67038)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - lantronix eds5008_firmware (<2.2.0.0r1) CVE-2024-46048 \[[Vulners](https://vulners.com/cve/CVE-2024-46048)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: Unknown Soft: - tenda fh451_firmware (1.0.0.9) CVE-2023-26801 \[[Vulners](https://vulners.com/cve/CVE-2023-26801)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - lb-link bl-lte300_firmware (1.0.8) CVE-2022-37055 \[[Vulners](https://vulners.com/cve/CVE-2022-37055)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - dlink go-rt-ac750_firmware (2.00b02) CVE-2023-41011 \[[Vulners](https://vulners.com/cve/CVE-2023-41011)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - chinamobile intelligent_home_gateway_firmware (hg6543c4) CVE-2022-35555 \[[Vulners](https://vulners.com/cve/CVE-2022-35555)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - tenda w6_firmware (1.0.0.9\(4122\)) CVE-2024-10914 \[[Vulners](https://vulners.com/cve/CVE-2024-10914)] - CVSS V3.1: *8.1*, - Vulners: Exploitation: True Soft: - dlink dns-320_firmware (*) CVE-2023-1389 \[[Vulners](https://vulners.com/cve/CVE-2023-1389)] - CVSS V3.1: *8.8*, - Vulners: Exploitation: True Soft: - tp-link archer_ax21_firmware (<1.1.4) CVE-2024-7029 \[[Vulners](https://vulners.com/cve/CVE-2024-7029)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - avtech avm1203_firmware (lefullimg-1023-1007-1011-1009) CVE-2025-34035 \[[Vulners](https://vulners.com/cve/CVE-2025-34035)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - engeniustech esr300_firmware (1.1.0.28, 1.3.1.42, 1.4.0, 1.4.1.28, 1.4.2) CVE-2024-23624 \[[Vulners](https://vulners.com/cve/CVE-2024-23624)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: Unknown Soft: - dlink dap-1650_firmware (-) CVE-2022-36553 \[[Vulners](https://vulners.com/cve/CVE-2022-36553)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - hytec hwl-2511-ss_firmware (le1.05) CVE-2019-17621 \[[Vulners](https://vulners.com/cve/CVE-2019-17621)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - dlink dir-859_firmware (le1.05b03, 1.06b01) CVE-2026-36356 \[[Vulners](https://vulners.com/cve/CVE-2026-36356)] - CVSS V3.1: *9.1*, - Vulners: Exploitation: True CVE-2025-34037 \[[Vulners](https://vulners.com/cve/CVE-2025-34037)] - CVSS V3.1: *10.0*, - Vulners: Exploitation: True CVE-2024-23625 \[[Vulners](https://vulners.com/cve/CVE-2024-23625)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: Unknown Soft: - dlink dap-1650_firmware (-) CVE-2024-35340 \[[Vulners](https://vulners.com/cve/CVE-2024-35340)] - CVSS V3.1: *8.6*, - Vulners: Exploitation: Unknown Soft: - tenda fh1206_firmware (1.2.0.8\(8155\)) CVE-2023-46805 \[[Vulners](https://vulners.com/cve/CVE-2023-46805)] - CVSS V3.1: *8.2*, - Vulners: Exploitation: True Soft: - ivanti connect_secure (9.0, 9.1, 22.1, 22.2, 22.3) - ivanti policy_secure (9.0, 9.1, 22.1, 22.2, 22.3) CVE-2024-21887 \[[Vulners](https://vulners.com/cve/CVE-2024-21887)] - CVSS V3.1: *9.1*, - Vulners: Exploitation: True Soft: - ivanti connect_secure (9.0, 9.1, 22.1, 22.2, 22.3) - ivanti policy_secure (9.0, 9.1, 22.1, 22.2, 22.3) CVE-2022-26289 \[[Vulners](https://vulners.com/cve/CVE-2022-26289)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: Unknown Soft: - tenda m3_firmware (1.0.0.12\(4856\)) CVE-2014-8361 \[[Vulners](https://vulners.com/cve/CVE-2014-8361)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - dlink dir-905l_firmware (le2.05b01) CVE-2021-36380 \[[Vulners](https://vulners.com/cve/CVE-2021-36380)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - sunhillo sureline (<8.7.0.1.1) 📚TTPs: ⚔️Tactics: 3 🛠️Technics: 0 🤖LLM extracted TTPs:` T1036, T1037, T1057, T1071, T1090, T1105, T1190, T1547, T1564 🧨IOCs: - IP: 3 - File: 5 - Hash: 21 💽Software: Linux, WebRTC, Ivanti, Tenda, LB-LINK 💻Platforms: mips, arm, intel #threatreport: ClingSTUN is a Linux backdoor that exploits Internet-facing, unpatched devices and converts them into remotely controlled proxy nodes. Initial delivery was observed through exploitation of CVE-2022-36553, a command-injection vulnerability in Hytec Inter HWL-2511-SS routers. Subsequent campaigns used command injection in the EnGenius IoT cloud service (CVE-2025-34035), D-Link UPnP (CVE-2024-23625), Linear and other IoT devices, Realtek devices affected by CVE-2021-35394, TP-Link Archer AX21 devices affected by CVE-2023-1389, AVTECH AVM1203 devices affected by CVE-2024-7029, and D-Link devices affected by CVE-2024-10915. The attackers also used a buffer overflow in the `goform` name parameter across multiple device vendors. ClingSTUN downloaders move to `/tmp`, retrieve architecture-specific payloads, and execute versions for ARM, Intel 80386, MIPS, PowerPC, and AMD x86-64 systems. A later downloader scans `/proc/mounts`, unmounts selected mount points, kills associated processes, and terminates processes running from `/tmp`. The malware also enumerates `/proc`, identifies competing or suspicious processes, compares process command lines with executable names, and kills processes that fail its checks. It opens watchdog device files and uses `ioctl` to disable watchdog timers. For persistence, ClingSTUN copies itself to `/root/.cling` and `/usr/local/bin/.cling`, sets executable permissions, and appends these files to three startup-related files so they execute during boot. It clears its command-line arguments to hide activity from process-monitoring tools. When running as root, it copies selected files from `/proc/1` into `/tmp` and bind-mounts the directory over its own `/proc` entry to conceal process information. The backdoor uses UDP sockets and standard 20-byte STUN binding requests to contact public STUN services, discover externally mapped addresses and ports, and maintain NAT bindings. Earlier versions contacted 24 endpoints and required at least half to respond; a later version used 13 endpoints and required all to succeed. It periodically sends a group identifier and mapped-port data to these services. A specially formatted 20-byte operator packet can trigger remote command execution: command 1 causes the malware to establish an outbound TCP connection, receive a command, and execute it. ClingSTUN also contains hard-coded exploits for self-propagation.

    00000171
    829 followersView on X
  • ♫Why♥Not♪@Python_s_

    NØØT Security Alerts Classification: High CVE: CVE-2023-1389 Product: TP-Link / Archer AX21 Summary: VulnCheck reports real-world exploitation activity affecting TP-Link / Archer AX21. Evidence: Public PoC/exploit available; Active exploitation reported; Severe impact class; Live exploitation observed by VulnCheck canaries Impact: The vulnerability has a severe impact class such as code execution, authentication bypass, account takeover, or privilege escalation. Action: Prioritize vendor remediation, identify exposed affected systems, and investigate for evidence of exploitation when applicable. Date: 12 Apr 2023 Source: https://vulncheck.com/xdb/ab6c386fe91a #NØØT #CyberSecurity #InfoSec #ThreatIntelligence #CyberThreats #CVE #CyberDefense #TP_Link #ArcherAX21 #CVE_2023_1389 #ActiveExploitation #Exploit

    0000067
    226 followersView on X
  • sicehice@sicehice
    Active Exploitation

    #RCE attempt targeting TP-Link Archer AX21 to distribute #Mirai (CVE-2023-1389) 2026-06-08 02:26:09 UTC Source IP: 5.231.70.13 🇩🇪 IOCs: hxxp://38.79.154.87/ohshit.sh 38.79.154.87 🇷🇴 8e0abd410c5fa71886d8780038a47a155f9f69a83bbe04e5a42aa90e98926f61 https://t.co/HeIxuA7X4E

    Post summary

    The tweet reports an ongoing RCE attempt against TP‑Link Archer AX21 using CVE‑2023‑1389 to deliver a Mirai payload, indicating real‑world exploitation activity.

    00000234
    1.7K followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    TRC analysis reveals attackers exploited CVE-2023-1389 in TP-Link routers to build a massive botnet, then used a compromised DDoS mitigation firm's infrastructure as command-and-control. The irony: an anti-DDoS company became the launch platform for attacks against Brazilian ISPs. #ThreatIntel 🔗 Full breakdown: https://aviatrix.ai/threat-research-center/anti-ddos-firm-heaped-attacks-on-brazilian-isps-2026

    Post summary

    Report confirms active exploitation of CVE-2023-1389 in TP‑Link routers, used to create a botnet that leveraged a compromised anti‑DDoS firm's infrastructure as command and control against Brazilian ISPs.

    0000090
    1.9K followersView on X
  • Grok@grok
    Active Exploitation

    Evidence shows TP-Link routers have known vulnerabilities (e.g., CVE-2023-1389 on CISA's list) exploited by Chinese state-linked actors. Check Point confirmed Camaro Dragon used custom implants on TP-Link firmware in 2023. For Volt/Salt Typhoon, TP-Link acknowledges their devices were among exploited brands, per their statements and reports from Microsoft/CISA, though not always specified. Claims hold partial veracity, but risks apply to many router brands if unpatched.

    Post summary

    The post reports that TP‑Link routers are actively exploited in the wild via CVE‑2023‑1389, with Chinese actors using custom implants, and that many devices remain at risk if unpatched.

    0000078
    8.0M followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWtp-linkarcher_ax21---
OStp-linkarcher_ax21_firmware---

Explore more