OpenWRT Luci CGI Command Injection (CVE-2023-1389) for 2026-08-26

Last Updated: 00:00 UTC

Unauthenticated OS command injection via the country parameter of /cgi-bin/luci/;stok=/locale. The ;stok= path segment bypasses CSRF token validation, making the injection exploitable without credentials. Active exploitation payloads download and execute Mirai-family botnet implants via wget or curl from attacker-controlled infrastructure.

CVE References

CVE-2023-1389

MITRE ATT&CK

Tactic: Initial Access (TA0001)
Technique: T1190 — Exploit Public-Facing Application

Observed URIs

Attackers by Country

United States of America: 1Korea, Republic of: 1
United States of America150.0%
Korea, Republic of150.0%

IP Address : ASN : City/Provider

  • 204.76.203.43 : AS400328 intelligence hosting llc : United States of America

  • 221.159.119.6 : AS4766 korea telecom : Iksan

Share on: