Causal model
What has to happen for this consequence to hold?
3 candidate paths · explicit source, inference, and assumption boundaries.
Authority · Co-dominant path
Account authority
The attacker obtains root administration of the gateway and its routing, DNS, and command surface, but not TP-Link's signing root.
Network-reachable without prior access
The vulnerable Archer AX21 management service was reachable from the network and was exploited on WAN-exposed routers in the wild.
EvidenceNVD
Cross-domain authority chain
A compromised gateway bridges the internet-facing service into every downstream client network and enables lateral movement.
EvidenceNo direct citation — inspect the declared inference or assumption.
Administrative or command authority
The attacker obtains root administration of the gateway and its routing, DNS, and command surface, but not TP-Link's signing root.
EvidenceNo direct citation — inspect the declared inference or assumption.
Account authority
The attacker obtains root administration of the gateway and its routing, DNS, and command surface, but not TP-Link's signing root.
EvidenceNo direct citation — inspect the declared inference or assumption.
Coordinated operational recovery
Each router needs fixed firmware and a factory reset or compromise review before its gateway state can be trusted again.
EvidenceNo direct citation — inspect the declared inference or assumption.
Decision rationale
Why this band?
The compact score is separated into the facts and judgments that produced it.
Reach and effort
- Reachability
RE 4 - Network-reachable without prior access
The vulnerable Archer AX21 management service was reachable from the network and was exploited on WAN-exposed routers in the wild.
- Execution complexity
EC 4 - Straightforward operation
One unauthenticated request is implemented in public exploit frameworks and automated botnet scanners.
- Exposure
EX 4 - Reach and effort support the same exposure
The documented reach and required effort are equally permissive, so neither reduces the other.
Consequence
- Physical / safety
PH 2 - Operational safety effect
Router takeover disrupts connectivity but does not directly control a physical actuator.
- Data / perception
DP 3 - Sensitive device or personal data
Root access exposes gateway credentials, network configuration, and traffic-handling state.
- Authority
AT 3 - Administrative or command authority
The attacker obtains root administration of the gateway and its routing, DNS, and command surface, but not TP-Link's signing root.
Scale and recovery
- Chainability
CH 4 - Cross-domain authority chain
A compromised gateway bridges the internet-facing service into every downstream client network and enables lateral movement.
- Reuse scale
SR 4 - Shared fleet-wide primitive
The same command-injection primitive applies across the affected Archer AX21 firmware population.
- Execution scale
SX 4 - Remote fleet-scale execution
Botnet scanners can enroll exposed routers remotely without a per-device secret or physical visit.
- Recovery burden
OR 3 - Coordinated operational recovery
Each router needs fixed firmware and a factory reset or compromise review before its gateway state can be trusted again.
Confidence and status
- Evidence strength
EV 4 - Field-confirmed evidence
NVD supports a reproduced or strongly report-backed condition; this registry still keeps consequence review separate from exploit confirmation.
- Liveness
LS Patch available - A patch is available
A vendor fix is available, while deployment and upgrade completion remain separate operational questions.
Decision trail
How the final band follows
- Base bandCRITICAL
- Systemic uplift
The CRITICAL base band rises to EMERGENCY because the remote root exploit was used by Mirai at scale across exposed routers and recovery requires coordinated patching or replacement.
- Final candidate bandEMERGENCY
Technical vector
CPATH:1.0-candidate/TT:ACCOUNT_AUTHORITY/RE:4/EC:4/EX:4/PH:2/DP:3/AT:3/CH:4/SR:4/SX:4/OR:3/EV:4/LS:PATCH_AVAILABLERead the scoring method →Systemic · Co-dominant path
Fleet control plane
The attacker controls a large population of rooted gateways through botnet command and control.
Network-reachable without prior access
WAN-exposed affected routers can be found and reached directly from the internet.
EvidenceNVD
Cross-domain authority chain
One router flaw becomes a distributed control plane that spans customer networks and the public internet.
EvidenceNo direct citation — inspect the declared inference or assumption.
Administrative or command authority
The attacker controls a large population of rooted gateways through botnet command and control.
EvidenceNo direct citation — inspect the declared inference or assumption.
Fleet control plane
The attacker controls a large population of rooted gateways through botnet command and control.
EvidenceNo direct citation — inspect the declared inference or assumption.
Coordinated operational recovery
Operators must patch and reset each enrolled router; leaving one node compromised preserves botnet access at that site.
EvidenceNo direct citation — inspect the declared inference or assumption.
Decision rationale
Why this band?
The compact score is separated into the facts and judgments that produced it.
Reach and effort
- Reachability
RE 4 - Network-reachable without prior access
WAN-exposed affected routers can be found and reached directly from the internet.
- Execution complexity
EC 4 - Straightforward operation
Automated scanners issue the same public command-injection request to each discovered router.
- Exposure
EX 4 - Reach and effort support the same exposure
The documented reach and required effort are equally permissive, so neither reduces the other.
Consequence
- Physical / safety
PH 2 - Operational safety effect
Large-scale router compromise can interrupt connectivity, while direct physical harm is outside this path.
- Data / perception
DP 2 - Operational data in scope
The botnet gains device inventory, network position, and operational telemetry from enrolled gateways.
- Authority
AT 3 - Administrative or command authority
The attacker controls a large population of rooted gateways through botnet command and control.
Scale and recovery
- Chainability
CH 4 - Cross-domain authority chain
One router flaw becomes a distributed control plane that spans customer networks and the public internet.
- Reuse scale
SR 4 - Shared fleet-wide primitive
A single portable exploit implementation works across the affected router population.
- Execution scale
SX 4 - Remote fleet-scale execution
Remote scanning and exploitation enroll routers at fleet scale without local setup.
- Recovery burden
OR 3 - Coordinated operational recovery
Operators must patch and reset each enrolled router; leaving one node compromised preserves botnet access at that site.
Confidence and status
- Evidence strength
EV 4 - Field-confirmed evidence
NVD supports a reproduced or strongly report-backed condition; this registry still keeps consequence review separate from exploit confirmation.
- Liveness
LS Patch available - A patch is available
A vendor fix is available, while deployment and upgrade completion remain separate operational questions.
Decision trail
How the final band follows
- Base bandCRITICAL
- Systemic uplift
The CRITICAL base band rises to EMERGENCY because botnet command and control aggregates the reusable router exploit across a large exposed population.
- Final candidate bandEMERGENCY
Technical vector
CPATH:1.0-candidate/TT:FLEET_CONTROL_PLANE/RE:4/EC:4/EX:4/PH:2/DP:2/AT:3/CH:4/SR:4/SX:4/OR:3/EV:4/LS:PATCH_AVAILABLERead the scoring method →Privacy · Supporting path
Data privacy
Gateway control exposes credentials and sensitive traffic from every client that routes through the compromised device.
Network-reachable without prior access
This path begins with the same internet-reachable command-injection service on the gateway.
EvidenceNVD
Cross-domain authority chain
The gateway compromise crosses from device administration into the data plane of all connected clients.
EvidenceNo direct citation — inspect the declared inference or assumption.
Sensitive device or personal data
Gateway control exposes credentials and sensitive traffic from every client that routes through the compromised device.
EvidenceNo direct citation — inspect the declared inference or assumption.
Data privacy
Gateway control exposes credentials and sensitive traffic from every client that routes through the compromised device.
EvidenceNo direct citation — inspect the declared inference or assumption.
Coordinated operational recovery
Restoration requires fixed firmware, reset of the gateway, and review of DNS, routing, and exposed credentials.
EvidenceNo direct citation — inspect the declared inference or assumption.
Decision rationale
Why this band?
The compact score is separated into the facts and judgments that produced it.
Reach and effort
- Reachability
RE 4 - Network-reachable without prior access
This path begins with the same internet-reachable command-injection service on the gateway.
- Execution complexity
EC 4 - Straightforward operation
Once root is obtained, changing DNS, routing, or packet handling to intercept client traffic is a routine administrator operation.
- Exposure
EX 4 - Reach and effort support the same exposure
The documented reach and required effort are equally permissive, so neither reduces the other.
Consequence
- Physical / safety
PH 2 - Operational safety effect
Traffic interception is a confidentiality and integrity harm, not direct physical actuation.
- Data / perception
DP 3 - Sensitive device or personal data
Gateway control exposes credentials and sensitive traffic from every client that routes through the compromised device.
- Authority
AT 3 - Administrative or command authority
Root authority over routing and DNS lets the attacker redirect or observe downstream communications.
Scale and recovery
- Chainability
CH 4 - Cross-domain authority chain
The gateway compromise crosses from device administration into the data plane of all connected clients.
- Reuse scale
SR 4 - Shared fleet-wide primitive
The same router exploit and interception setup can be reused across affected devices.
- Execution scale
SX 4 - Remote fleet-scale execution
Each remotely compromised gateway exposes the traffic of its attached network, allowing broad repeated collection.
- Recovery burden
OR 3 - Coordinated operational recovery
Restoration requires fixed firmware, reset of the gateway, and review of DNS, routing, and exposed credentials.
Confidence and status
- Evidence strength
EV 3 - Reproduced or strongly report-backed
NVD supports a reproduced or strongly report-backed condition; this registry still keeps consequence review separate from exploit confirmation.
- Liveness
LS Patch available - A patch is available
A vendor fix is available, while deployment and upgrade completion remain separate operational questions.
Decision trail
How the final band follows
- Base bandCRITICAL
- No adjustment
The CRITICAL base band remains final because no separate cap or systemic uplift applies. Gateway control exposes credentials and sensitive traffic from every client that routes through the compromised device.
- Final candidate bandCRITICAL
Technical vector
CPATH:1.0-candidate/TT:DATA_PRIVACY/RE:4/EC:4/EX:4/PH:2/DP:3/AT:3/CH:4/SR:4/SX:4/OR:3/EV:3/LS:PATCH_AVAILABLERead the scoring method →Triage implication
Verify the authority transition before acting on the band.
Triage beyond the first device: verify whether the reusable condition, propagation mechanism, and recovery dependency actually exist across the deployment.
Evidence ledger
Public sources used by this record.
Every named source includes a public link. Path review remains separate from citation coverage.
- advisoryNVD
NVD
Published baseline
Keep exploit severity and consequence reasoning distinct.
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HCVE recordsCVE-2023-1389
Original scorer notes
The source narrative behind the structured explanation.
Retained for provenance and historical review, not as the recommended way to understand the assessment.
Read the original scorer notes
Assessment
CFSE Consequence Paths assesses TP-Link Archer AX21 (AX1800) router unauthenticated command injection (CVE-2023-1389) at EMERGENCY — the worst of 3 risk paths (authority, perception). The dominant consequence is privileged account or control authority.
Vulnerability
TP-Link Archer AX21 (AX1800) router unauthenticated command injection (CVE-2023-1389). Reported attack vector: Adjacent network (AV:A per NVD; reachable on LAN/Wi-Fi, and exploited at Internet scale where the management interface is WAN-exposed).
CFSE Consequence Paths analysis
The vulnerability is decomposed into one risk path per terminal consequence. Each path is scored on its exposure (reachability × execution complexity) and the authority, perception, and physical/safety it reaches, together with its scale of reuse, scale of execution, and recoverability.
ACCOUNT_AUTHORITY → EMERGENCY
CPATH:1.0-candidate/TT:ACCOUNT_AUTHORITY/RE:4/EC:4/EX:4/PH:2/DP:3/AT:3/CH:4/SR:4/SX:4/OR:3/EV:4/LS:PATCH_AVAILABLE
Exposure EX=4 (reachability and complexity-bound) · bands PH=CRITICAL · DP=CRITICAL · AT=CRITICAL → base CRITICAL · uplift active exploitation, fleet-reachable authority → assessed EMERGENCY.
Unauthenticated POST to the locale ‘country’ parameter yields arbitrary command execution as root on the gateway. RE:4 because exploited Internet-wide against WAN-exposed management interfaces (LAN/Wi-Fi at minimum, but mass remote exploitation observed). EC:4 single unauthenticated request, public Metasploit/ExploitDB PoC. AT:3 root/admin authority over the gateway device (modifies device config/firmware/command surface) but not a signing-root or OTA-root of trust, so not 4. PH:2 network device, no direct actuation; perimeter control can disrupt availability but no severe physical harm. DP:3 root control exposes credentials and sensitive operational state. CH:4 root on the gateway is a reusable multi-hop bridge crossing network/device boundaries enabling lateral movement and pivot. SR:4 identical primitive across the whole Archer AX21/AX1800 population. SX:4 fleet-scale remote exploitation without per-device access. OR:3 recoverable via firmware 1.1.4+ and factory reset per device; not fleet-reprovision/recall. EV:4 field-confirmed, CISA KEV.
FLEET_CONTROL_PLANE → EMERGENCY
CPATH:1.0-candidate/TT:FLEET_CONTROL_PLANE/RE:4/EC:4/EX:4/PH:2/DP:2/AT:3/CH:4/SR:4/SX:4/OR:3/EV:4/LS:PATCH_AVAILABLE
Exposure EX=4 (reachability and complexity-bound) · bands PH=CRITICAL · DP=HIGH · AT=CRITICAL → base CRITICAL · uplift active exploitation, fleet-reachable authority → assessed EMERGENCY.
The single reusable RCE primitive was rapidly weaponized into multiple Mirai botnet variants, enrolling routers at scale into attacker command-and-control. RE:4 Internet-wide reachable/exploited. EC:4 trivial single request, automated botnet scanning. AT:3 attacker gains command authority over a large device population aggregated under botnet C2; this is fleet-scale control of compromised nodes but via a per-device exploit reused at scale rather than a manufacturer OTA/signing root, so AT:3 not 4. PH:2 no severe physical harm; availability/DDoS impact. DP:2 telemetry/network position. CH:4 cross-domain bridge: one bug becomes a botnet control plane spanning the device fleet and the Internet. SR:4 single shared primitive portable across the entire product line. SX:4 fleet-scale remote enrollment with no per-device access. OR:3 each node recoverable via patch+reset; no manufacturer recall/key rotation needed. EV:4 field-confirmed Mirai variants, KEV-listed.
DATA_PRIVACY → CRITICAL
CPATH:1.0-candidate/TT:DATA_PRIVACY/RE:4/EC:4/EX:4/PH:2/DP:3/AT:3/CH:4/SR:4/SX:4/OR:3/EV:3/LS:PATCH_AVAILABLE
Exposure EX=4 (reachability and complexity-bound) · bands PH=CRITICAL · DP=CRITICAL · AT=CRITICAL → base CRITICAL · uplift active exploitation, fleet-reachable authority · caps privacy-only cap → assessed CRITICAL.
Root control of the gateway enables traffic interception/redirection (DNS hijack, MITM) affecting all downstream client data. RE:4 same Internet-reachable entry point. EC:4 once root is held, configuring DNS/routing for MITM is trivial. AT:3 admin/root authority over the network perimeter; not a trust-root. PH:2 no severe physical harm. DP:3 sensitive: all downstream client traffic confidentiality/integrity (credentials, sensitive op-state) is compromised; not 4 because it is network data plane, not biometric/spatial-map/safety-sensor world-model state, and it does not drive physical/safety action so perception_feeds_action=false. CH:4 reusable cross-boundary bridge (device control to data-plane interception across all clients). SR:4 same primitive across product population. SX:4 every compromised gateway exposes all its clients at fleet scale. OR:3 recoverable per device via patch/reset. EV:3 interception capability is a credible/reproduced consequence of root rather than the field-headline behavior (botnet enrollment), so slightly lower evidence than the takeover/botnet paths.
Published baseline
- v3.1 8.8 HIGH —
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H— NVD / CNA via NVD
The published baseline above is retained for source review. The registry records the reachable consequence path, including deployment-specific cyber-physical consequence, physical/safety impact, scale, and recovery burden.
Sources
CFSE Consequence Paths Registry 1.0-candidate, CPATH-2026-0031 (“TP-Link Archer AX21 (AX1800) router unauthenticated command injection (CVE-2023-1389)”), paths.cfse.ai/CPATH-2026-0031 (published 2026-06-03).