TP-Link Archer AX21 (AX1800) routers are vulnerable to unauthenticated OS command injection via the country parameter in the locale endpoint. This allows remote attackers to execute arbitrary commands as root.
id: CVE-2023-1389
info:
name: TP-Link Archer AX21 (AX1800) - Unauthenticated Command Injection
...