7.5
CWE
834
Advisory Published
Updated

CVE-2021-3128

First published: Mon Apr 12 2021(Updated: )

In ASUS RT-AX3000, ZenWiFi AX (XT8), RT-AX88U, and other ASUS routers with firmware < 3.0.0.4.386.42095 or < 9.0.0.4.386.41994, when IPv6 is used, a routing loop can occur that generates excessive network traffic between an affected device and its upstream ISP's router. This occurs when a link prefix route points to a point-to-point link, a destination IPv6 address belongs to the prefix and is not a local IPv6 address, and a router advertisement is received with at least one global unique IPv6 prefix for which the on-link flag is set.

Credit: cve@mitre.org

Affected SoftwareAffected VersionHow to fix
ASUS ZenWiFi AX (xt8) Firmware<3.0.0.4.386.42095
ASUS ZenWiFi AX (xt8)
ASUS ZenWiFi AX (xt8) Firmware<9.0.0.4.386.41994
ASUS TUF Gaming AX3000 V2 Firmware<3.0.0.4.386.42095
ASUS routers
ASUS TUF Gaming AX3000 V2 Firmware<9.0.0.4.386.41994
ASUS RT-AX55 Firmware<3.0.0.4.386.42095
ASUS routers
ASUS RT-AX55 Firmware<9.0.0.4.386.41994
ASUS RT-AX56U V2 firmware<3.0.0.4.386.42095
ASUS RT-AX56U firmware
ASUS RT-AX56U V2 firmware<9.0.0.4.386.41994
ASUS RT-AX58U Firmware<3.0.0.4.386.42095
ASUS RT-AX58U Firmware
ASUS RT-AX58U Firmware<9.0.0.4.386.41994
ASUS RT-AX68U<3.0.0.4.386.42095
ASUS RT-AX68U Firmware
ASUS RT-AX68U<9.0.0.4.386.41994
Asus RT-AX82U firmware<3.0.0.4.386.42095
Asus RT-AX82U firmware
Asus RT-AX82U firmware<9.0.0.4.386.41994
ASUS RT-AX86U ZAKU II EDITION firmware<3.0.0.4.386.42095
ASUS RT-AX86
ASUS RT-AX86U ZAKU II EDITION firmware<9.0.0.4.386.41994
ASUS RT-AX88U Firmware<3.0.0.4.386.42095
ASUS RT-AX88U Firmware
ASUS RT-AX88U Firmware<9.0.0.4.386.41994
ASUS RT-AC66U B1<3.0.0.4.386.42095
ASUS RT-AC66U firmware
ASUS RT-AC66U B1<9.0.0.4.386.41994
ASUS RT-AC1750 firmware<3.0.0.4.386.42095
ASUS RT-AC1750
ASUS RT-AC1750 firmware<9.0.0.4.386.41994
ASUS RT-AC1900U Firmware<3.0.0.4.386.42095
ASUS RT-AC1900 Firmware
ASUS RT-AC1900U Firmware<9.0.0.4.386.41994
ASUS RT-AC1900P Firmware<3.0.0.4.386.42095
ASUS RT-AC1900P Firmware
ASUS RT-AC1900P Firmware<9.0.0.4.386.41994
ASUS RT-AC1900 Firmware<3.0.0.4.386.42095
ASUS RT-AC1900U Firmware
ASUS RT-AC1900 Firmware<9.0.0.4.386.41994
ASUS ROG Rapture GT-AC2900 Firmware<3.0.0.4.386.42095
ASUS RT-AC2900 firmware
ASUS ROG Rapture GT-AC2900 Firmware<9.0.0.4.386.41994
ASUS RT-AC3100 Firmware<3.0.0.4.386.42095
ASUS RT-AC3100
ASUS RT-AC3100 Firmware<9.0.0.4.386.41994
ASUS RT-AC5300 firmware<3.0.0.4.386.42095
ASUS RT-AC5300 firmware
ASUS RT-AC5300 firmware<9.0.0.4.386.41994
ASUS RT-AC58U firmware<3.0.0.4.386.42095
ASUS RT-AC58U firmware
ASUS RT-AC58U firmware<9.0.0.4.386.41994
ASUS RT-AC65U Firmware<3.0.0.4.386.42095
ASUS RT-AC65U Firmware
ASUS RT-AC65U Firmware<9.0.0.4.386.41994
ASUS RT-AC68P Firmware<3.0.0.4.386.42095
ASUS RT-AC68P Firmware
ASUS RT-AC68P Firmware<9.0.0.4.386.41994
ASUS RT-AC68R<3.0.0.4.386.42095
ASUS RT-AC68R Firmware
ASUS RT-AC68R<9.0.0.4.386.41994
ASUS RT-AC68RW<3.0.0.4.386.42095
ASUS RT-AC68RW Firmware
ASUS RT-AC68RW<9.0.0.4.386.41994
ASUS RT-AC68R<3.0.0.4.386.42095
ASUS 4G-AC68U
ASUS RT-AC68R<9.0.0.4.386.41994
ASUS RT-AC68W Firmware<3.0.0.4.386.42095
ASUS RT-AC68W
ASUS RT-AC68W Firmware<9.0.0.4.386.41994
ASUS RT-AC85U Firmware<3.0.0.4.386.42095
ASUS RT-AC85U Firmware
ASUS RT-AC85U Firmware<9.0.0.4.386.41994
ASUS RT-AC86U Firmware<3.0.0.4.386.42095
ASUS RT-AC86U firmware
ASUS RT-AC86U Firmware<9.0.0.4.386.41994
ASUS RT-AC88U Firmware<3.0.0.4.386.42095
ASUS RT-AC88U Firmware
ASUS RT-AC88U Firmware<9.0.0.4.386.41994

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Reference Links

Frequently Asked Questions

  • What is the severity of CVE-2021-3128?

    CVE-2021-3128 is considered a high-severity vulnerability due to the potential for significant network disruption.

  • How do I fix CVE-2021-3128?

    To fix CVE-2021-3128, update your ASUS router firmware to versions 3.0.0.4.386.42095 or later, or 9.0.0.4.386.41994 or later.

  • Which ASUS router models are affected by CVE-2021-3128?

    CVE-2021-3128 affects various ASUS routers including RT-AX3000, ZenWiFi AX (XT8), and RT-AX88U with outdated firmware.

  • What type of issue does CVE-2021-3128 cause in affected routers?

    CVE-2021-3128 can cause a routing loop that leads to excessive network traffic and potential service interruptions.

  • Is CVE-2021-3128 an IPv6 related vulnerability?

    Yes, CVE-2021-3128 specifically triggers a vulnerability when IPv6 is used in the affected ASUS routers.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203