CVE-2021-32030: ASUS Routers Improper Authentication Vulnerability
ASUS Lyra Mini and ASUS GT-AC2900 devices contain an improper authentication vulnerability that allows an attacker to gain unauthorized access to the administrative interface. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.
Other sources
The administrator application on ASUS GT-AC2900 devices before 3.0.0.4.386.42643 allows authentication bypass when processing remote input from an unauthenticated user, leading to unauthorized access to the administrator interface. This relates to handlerequest in router/httpd/httpd.c and authcheck in webhook.o. An attacker-supplied value of '\0' matches the device's default value of '\0' in some situations.
The administrator application on ASUS GT-AC2900 devices before 3.0.0.4.386.42643 and Lyra Mini before 3.0.0.438446630 allows authentication bypass when processing remote input from an unauthenticated user, leading to unauthorized access to the administrator interface. This relates to handlerequest in router/httpd/httpd.c and authcheck in webhook.o. An attacker-supplied value of '\0' matches the device's default value of '\0' in some situations. Note: All versions of Lyra Mini and earlier which are unsupported (End-of-Life, EOL) are also affected by this vulnerability, Consumers can mitigate this vulnerability by disabling the remote access features from WAN.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ASUS GT-AC2900to a version that resolves this vulnerability.Fixed in 3.0.0.4.386.42643 - Upgrade
Upgrade
ASUS Lyra Minito a version that resolves this vulnerability.Fixed in 3.0.0.4_384_46630 - Configuration
Disable the remote access features from WAN to mitigate the authentication vulnerability.
ASUS routers remote access features from WAN = disabled - Compensating control
Discontinue use of impacted ASUS Lyra Mini and ASUS GT-AC2900 products.
Event History
Frequently Asked Questions
What is the vulnerability ID for this ASUS GT-AC2900 vulnerability?
The vulnerability ID is CVE-2021-32030.
What is the severity of CVE-2021-32030?
The severity of CVE-2021-32030 is critical with a severity value of 9.8.
How does CVE-2021-32030 affect ASUS GT-AC2900 devices?
CVE-2021-32030 allows authentication bypass when processing remote input from an unauthenticated user, leading to unauthorized access to the administrator interface.
Which version of ASUS GT-AC2900 devices are affected by CVE-2021-32030?
ASUS GT-AC2900 devices before version 3.0.0.4.386.42643 are affected by CVE-2021-32030.
How do I fix CVE-2021-32030 on my ASUS GT-AC2900 device?
To fix CVE-2021-32030, you should update your ASUS GT-AC2900 device to version 3.0.0.4.386.42643 or later.