CPATH-2026-0031 · General IoT

TP-Link Archer AX21 (AX1800) router unauthenticated command injection (CVE-2023-1389)

Two or more co-dominant consequence paths connect the public security record to a provisional EMERGENCY consequence band.

Candidate bandEMERGENCY
Co-dominant pathsAccount authority + Fleet control plane

These paths are co-dominant because each reaches the record's highest candidate band, EMERGENCY; no array-order tie-break is applied.

Causal model

What has to happen for this consequence to hold?

3 candidate paths · explicit source, inference, and assumption boundaries.

Authority · Co-dominant path

Account authority

The attacker obtains root administration of the gateway and its routing, DNS, and command surface, but not TP-Link's signing root.

EMERGENCY
  1. accessSource-backed

    Network-reachable without prior access

    The vulnerable Archer AX21 management service was reachable from the network and was exploited on WAN-exposed routers in the wild.

    EvidenceNVD

  2. boundaryModel inference

    Cross-domain authority chain

    A compromised gateway bridges the internet-facing service into every downstream client network and enables lateral movement.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  3. capabilityModel inference

    Administrative or command authority

    The attacker obtains root administration of the gateway and its routing, DNS, and command surface, but not TP-Link's signing root.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  4. consequenceModel inference

    Account authority

    The attacker obtains root administration of the gateway and its routing, DNS, and command surface, but not TP-Link's signing root.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  5. recoveryOperational assumption

    Coordinated operational recovery

    Each router needs fixed firmware and a factory reset or compromise review before its gateway state can be trusted again.

    EvidenceNo direct citation — inspect the declared inference or assumption.

Decision rationale

Why this band?

The compact score is separated into the facts and judgments that produced it.

Reach and effort
ReachabilityRE 4
Network-reachable without prior access

The vulnerable Archer AX21 management service was reachable from the network and was exploited on WAN-exposed routers in the wild.

Source-backedNVD
Execution complexityEC 4
Straightforward operation

One unauthenticated request is implemented in public exploit frameworks and automated botnet scanners.

Source-backedNVD
ExposureEX 4
Reach and effort support the same exposure

The documented reach and required effort are equally permissive, so neither reduces the other.

Model inference
Consequence
Physical / safetyPH 2
Operational safety effect

Router takeover disrupts connectivity but does not directly control a physical actuator.

Model inference
Data / perceptionDP 3
Sensitive device or personal data

Root access exposes gateway credentials, network configuration, and traffic-handling state.

Model inference
AuthorityAT 3
Administrative or command authority

The attacker obtains root administration of the gateway and its routing, DNS, and command surface, but not TP-Link's signing root.

Model inference
Scale and recovery
ChainabilityCH 4
Cross-domain authority chain

A compromised gateway bridges the internet-facing service into every downstream client network and enables lateral movement.

Model inference
Reuse scaleSR 4
Shared fleet-wide primitive

The same command-injection primitive applies across the affected Archer AX21 firmware population.

Operational assumption
Execution scaleSX 4
Remote fleet-scale execution

Botnet scanners can enroll exposed routers remotely without a per-device secret or physical visit.

Operational assumption
Recovery burdenOR 3
Coordinated operational recovery

Each router needs fixed firmware and a factory reset or compromise review before its gateway state can be trusted again.

Operational assumption
Confidence and status
Evidence strengthEV 4
Field-confirmed evidence

NVD supports a reproduced or strongly report-backed condition; this registry still keeps consequence review separate from exploit confirmation.

Source-backedNVD
LivenessLS Patch available
A patch is available

A vendor fix is available, while deployment and upgrade completion remain separate operational questions.

Source-backedNVD

Decision trail

How the final band follows

  1. Base bandCRITICAL
  2. Systemic uplift

    The CRITICAL base band rises to EMERGENCY because the remote root exploit was used by Mirai at scale across exposed routers and recovery requires coordinated patching or replacement.

  3. Final candidate bandEMERGENCY
Technical vector
Compact machine notationCPATH:1.0-candidate/TT:ACCOUNT_AUTHORITY/RE:4/EC:4/EX:4/PH:2/DP:3/AT:3/CH:4/SR:4/SX:4/OR:3/EV:4/LS:PATCH_AVAILABLERead the scoring method →

Systemic · Co-dominant path

Fleet control plane

The attacker controls a large population of rooted gateways through botnet command and control.

EMERGENCY
  1. accessSource-backed

    Network-reachable without prior access

    WAN-exposed affected routers can be found and reached directly from the internet.

    EvidenceNVD

  2. boundaryModel inference

    Cross-domain authority chain

    One router flaw becomes a distributed control plane that spans customer networks and the public internet.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  3. capabilityModel inference

    Administrative or command authority

    The attacker controls a large population of rooted gateways through botnet command and control.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  4. consequenceModel inference

    Fleet control plane

    The attacker controls a large population of rooted gateways through botnet command and control.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  5. recoveryOperational assumption

    Coordinated operational recovery

    Operators must patch and reset each enrolled router; leaving one node compromised preserves botnet access at that site.

    EvidenceNo direct citation — inspect the declared inference or assumption.

Decision rationale

Why this band?

The compact score is separated into the facts and judgments that produced it.

Reach and effort
ReachabilityRE 4
Network-reachable without prior access

WAN-exposed affected routers can be found and reached directly from the internet.

Source-backedNVD
Execution complexityEC 4
Straightforward operation

Automated scanners issue the same public command-injection request to each discovered router.

Source-backedNVD
ExposureEX 4
Reach and effort support the same exposure

The documented reach and required effort are equally permissive, so neither reduces the other.

Model inference
Consequence
Physical / safetyPH 2
Operational safety effect

Large-scale router compromise can interrupt connectivity, while direct physical harm is outside this path.

Model inference
Data / perceptionDP 2
Operational data in scope

The botnet gains device inventory, network position, and operational telemetry from enrolled gateways.

Model inference
AuthorityAT 3
Administrative or command authority

The attacker controls a large population of rooted gateways through botnet command and control.

Model inference
Scale and recovery
ChainabilityCH 4
Cross-domain authority chain

One router flaw becomes a distributed control plane that spans customer networks and the public internet.

Model inference
Reuse scaleSR 4
Shared fleet-wide primitive

A single portable exploit implementation works across the affected router population.

Operational assumption
Execution scaleSX 4
Remote fleet-scale execution

Remote scanning and exploitation enroll routers at fleet scale without local setup.

Operational assumption
Recovery burdenOR 3
Coordinated operational recovery

Operators must patch and reset each enrolled router; leaving one node compromised preserves botnet access at that site.

Operational assumption
Confidence and status
Evidence strengthEV 4
Field-confirmed evidence

NVD supports a reproduced or strongly report-backed condition; this registry still keeps consequence review separate from exploit confirmation.

Source-backedNVD
LivenessLS Patch available
A patch is available

A vendor fix is available, while deployment and upgrade completion remain separate operational questions.

Source-backedNVD

Decision trail

How the final band follows

  1. Base bandCRITICAL
  2. Systemic uplift

    The CRITICAL base band rises to EMERGENCY because botnet command and control aggregates the reusable router exploit across a large exposed population.

  3. Final candidate bandEMERGENCY
Technical vector
Compact machine notationCPATH:1.0-candidate/TT:FLEET_CONTROL_PLANE/RE:4/EC:4/EX:4/PH:2/DP:2/AT:3/CH:4/SR:4/SX:4/OR:3/EV:4/LS:PATCH_AVAILABLERead the scoring method →

Privacy · Supporting path

Data privacy

Gateway control exposes credentials and sensitive traffic from every client that routes through the compromised device.

CRITICAL
  1. accessSource-backed

    Network-reachable without prior access

    This path begins with the same internet-reachable command-injection service on the gateway.

    EvidenceNVD

  2. boundaryModel inference

    Cross-domain authority chain

    The gateway compromise crosses from device administration into the data plane of all connected clients.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  3. capabilityModel inference

    Sensitive device or personal data

    Gateway control exposes credentials and sensitive traffic from every client that routes through the compromised device.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  4. consequenceModel inference

    Data privacy

    Gateway control exposes credentials and sensitive traffic from every client that routes through the compromised device.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  5. recoveryOperational assumption

    Coordinated operational recovery

    Restoration requires fixed firmware, reset of the gateway, and review of DNS, routing, and exposed credentials.

    EvidenceNo direct citation — inspect the declared inference or assumption.

Decision rationale

Why this band?

The compact score is separated into the facts and judgments that produced it.

Reach and effort
ReachabilityRE 4
Network-reachable without prior access

This path begins with the same internet-reachable command-injection service on the gateway.

Source-backedNVD
Execution complexityEC 4
Straightforward operation

Once root is obtained, changing DNS, routing, or packet handling to intercept client traffic is a routine administrator operation.

Source-backedNVD
ExposureEX 4
Reach and effort support the same exposure

The documented reach and required effort are equally permissive, so neither reduces the other.

Model inference
Consequence
Physical / safetyPH 2
Operational safety effect

Traffic interception is a confidentiality and integrity harm, not direct physical actuation.

Model inference
Data / perceptionDP 3
Sensitive device or personal data

Gateway control exposes credentials and sensitive traffic from every client that routes through the compromised device.

Model inference
AuthorityAT 3
Administrative or command authority

Root authority over routing and DNS lets the attacker redirect or observe downstream communications.

Model inference
Scale and recovery
ChainabilityCH 4
Cross-domain authority chain

The gateway compromise crosses from device administration into the data plane of all connected clients.

Model inference
Reuse scaleSR 4
Shared fleet-wide primitive

The same router exploit and interception setup can be reused across affected devices.

Operational assumption
Execution scaleSX 4
Remote fleet-scale execution

Each remotely compromised gateway exposes the traffic of its attached network, allowing broad repeated collection.

Operational assumption
Recovery burdenOR 3
Coordinated operational recovery

Restoration requires fixed firmware, reset of the gateway, and review of DNS, routing, and exposed credentials.

Operational assumption
Confidence and status
Evidence strengthEV 3
Reproduced or strongly report-backed

NVD supports a reproduced or strongly report-backed condition; this registry still keeps consequence review separate from exploit confirmation.

Source-backedNVD
LivenessLS Patch available
A patch is available

A vendor fix is available, while deployment and upgrade completion remain separate operational questions.

Source-backedNVD

Decision trail

How the final band follows

  1. Base bandCRITICAL
  2. No adjustment

    The CRITICAL base band remains final because no separate cap or systemic uplift applies. Gateway control exposes credentials and sensitive traffic from every client that routes through the compromised device.

  3. Final candidate bandCRITICAL
Technical vector
Compact machine notationCPATH:1.0-candidate/TT:DATA_PRIVACY/RE:4/EC:4/EX:4/PH:2/DP:3/AT:3/CH:4/SR:4/SX:4/OR:3/EV:3/LS:PATCH_AVAILABLERead the scoring method →

Triage implication

Verify the authority transition before acting on the band.

Triage beyond the first device: verify whether the reusable condition, propagation mechanism, and recovery dependency actually exist across the deployment.

Evidence ledger

Public sources used by this record.

Every named source includes a public link. Path review remains separate from citation coverage.

Published baseline

Keep exploit severity and consequence reasoning distinct.

RelationshipPaths model is higher
Baseline confidencehigh
Scored2026-06-03
v3.1 · 8.8 HIGHNVD / CNA via NVD
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Original scorer notes

The source narrative behind the structured explanation.

Retained for provenance and historical review, not as the recommended way to understand the assessment.

Read the original scorer notes

Assessment

CFSE Consequence Paths assesses TP-Link Archer AX21 (AX1800) router unauthenticated command injection (CVE-2023-1389) at EMERGENCY — the worst of 3 risk paths (authority, perception). The dominant consequence is privileged account or control authority.

Vulnerability

TP-Link Archer AX21 (AX1800) router unauthenticated command injection (CVE-2023-1389). Reported attack vector: Adjacent network (AV:A per NVD; reachable on LAN/Wi-Fi, and exploited at Internet scale where the management interface is WAN-exposed).

CFSE Consequence Paths analysis

The vulnerability is decomposed into one risk path per terminal consequence. Each path is scored on its exposure (reachability × execution complexity) and the authority, perception, and physical/safety it reaches, together with its scale of reuse, scale of execution, and recoverability.

ACCOUNT_AUTHORITYEMERGENCY

CPATH:1.0-candidate/TT:ACCOUNT_AUTHORITY/RE:4/EC:4/EX:4/PH:2/DP:3/AT:3/CH:4/SR:4/SX:4/OR:3/EV:4/LS:PATCH_AVAILABLE

Exposure EX=4 (reachability and complexity-bound) · bands PH=CRITICAL · DP=CRITICAL · AT=CRITICAL → base CRITICAL · uplift active exploitation, fleet-reachable authority → assessed EMERGENCY.

Unauthenticated POST to the locale ‘country’ parameter yields arbitrary command execution as root on the gateway. RE:4 because exploited Internet-wide against WAN-exposed management interfaces (LAN/Wi-Fi at minimum, but mass remote exploitation observed). EC:4 single unauthenticated request, public Metasploit/ExploitDB PoC. AT:3 root/admin authority over the gateway device (modifies device config/firmware/command surface) but not a signing-root or OTA-root of trust, so not 4. PH:2 network device, no direct actuation; perimeter control can disrupt availability but no severe physical harm. DP:3 root control exposes credentials and sensitive operational state. CH:4 root on the gateway is a reusable multi-hop bridge crossing network/device boundaries enabling lateral movement and pivot. SR:4 identical primitive across the whole Archer AX21/AX1800 population. SX:4 fleet-scale remote exploitation without per-device access. OR:3 recoverable via firmware 1.1.4+ and factory reset per device; not fleet-reprovision/recall. EV:4 field-confirmed, CISA KEV.

FLEET_CONTROL_PLANEEMERGENCY

CPATH:1.0-candidate/TT:FLEET_CONTROL_PLANE/RE:4/EC:4/EX:4/PH:2/DP:2/AT:3/CH:4/SR:4/SX:4/OR:3/EV:4/LS:PATCH_AVAILABLE

Exposure EX=4 (reachability and complexity-bound) · bands PH=CRITICAL · DP=HIGH · AT=CRITICAL → base CRITICAL · uplift active exploitation, fleet-reachable authority → assessed EMERGENCY.

The single reusable RCE primitive was rapidly weaponized into multiple Mirai botnet variants, enrolling routers at scale into attacker command-and-control. RE:4 Internet-wide reachable/exploited. EC:4 trivial single request, automated botnet scanning. AT:3 attacker gains command authority over a large device population aggregated under botnet C2; this is fleet-scale control of compromised nodes but via a per-device exploit reused at scale rather than a manufacturer OTA/signing root, so AT:3 not 4. PH:2 no severe physical harm; availability/DDoS impact. DP:2 telemetry/network position. CH:4 cross-domain bridge: one bug becomes a botnet control plane spanning the device fleet and the Internet. SR:4 single shared primitive portable across the entire product line. SX:4 fleet-scale remote enrollment with no per-device access. OR:3 each node recoverable via patch+reset; no manufacturer recall/key rotation needed. EV:4 field-confirmed Mirai variants, KEV-listed.

DATA_PRIVACYCRITICAL

CPATH:1.0-candidate/TT:DATA_PRIVACY/RE:4/EC:4/EX:4/PH:2/DP:3/AT:3/CH:4/SR:4/SX:4/OR:3/EV:3/LS:PATCH_AVAILABLE

Exposure EX=4 (reachability and complexity-bound) · bands PH=CRITICAL · DP=CRITICAL · AT=CRITICAL → base CRITICAL · uplift active exploitation, fleet-reachable authority · caps privacy-only cap → assessed CRITICAL.

Root control of the gateway enables traffic interception/redirection (DNS hijack, MITM) affecting all downstream client data. RE:4 same Internet-reachable entry point. EC:4 once root is held, configuring DNS/routing for MITM is trivial. AT:3 admin/root authority over the network perimeter; not a trust-root. PH:2 no severe physical harm. DP:3 sensitive: all downstream client traffic confidentiality/integrity (credentials, sensitive op-state) is compromised; not 4 because it is network data plane, not biometric/spatial-map/safety-sensor world-model state, and it does not drive physical/safety action so perception_feeds_action=false. CH:4 reusable cross-boundary bridge (device control to data-plane interception across all clients). SR:4 same primitive across product population. SX:4 every compromised gateway exposes all its clients at fleet scale. OR:3 recoverable per device via patch/reset. EV:3 interception capability is a credible/reproduced consequence of root rather than the field-headline behavior (botnet enrollment), so slightly lower evidence than the takeover/botnet paths.

Published baseline

  • v3.1 8.8 HIGH — CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H — NVD / CNA via NVD

The published baseline above is retained for source review. The registry records the reachable consequence path, including deployment-specific cyber-physical consequence, physical/safety impact, scale, and recovery burden.

Sources

Related paths

Compare the boundary, not only the product.

Cite this entryCFSE Consequence Paths Registry 1.0-candidate, CPATH-2026-0031 (“TP-Link Archer AX21 (AX1800) router unauthenticated command injection (CVE-2023-1389)”), paths.cfse.ai/CPATH-2026-0031 (published 2026-06-03).