CVE-2021-32030: ASUS Routers Improper Authentication Vulnerability
ASUS Lyra Mini and ASUS GT-AC2900 devices contain an improper authentication vulnerability that allows an attacker to gain unauthorized access to the administrative interface. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.
Other sources
The administrator application on ASUS GT-AC2900 devices before 3.0.0.4.386.42643 allows authentication bypass when processing remote input from an unauthenticated user, leading to unauthorized access to the administrator interface. This relates to handlerequest in router/httpd/httpd.c and authcheck in webhook.o. An attacker-supplied value of '\0' matches the device's default value of '\0' in some situations.
The administrator application on ASUS GT-AC2900 devices before 3.0.0.4.386.42643 and Lyra Mini before 3.0.0.438446630 allows authentication bypass when processing remote input from an unauthenticated user, leading to unauthorized access to the administrator interface. This relates to handlerequest in router/httpd/httpd.c and authcheck in webhook.o. An attacker-supplied value of '\0' matches the device's default value of '\0' in some situations. Note: All versions of Lyra Mini and earlier which are unsupported (End-of-Life, EOL) are also affected by this vulnerability, Consumers can mitigate this vulnerability by disabling the remote access features from WAN.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ASUS GT-AC2900to a version that resolves this vulnerability.Fixed in 3.0.0.4.386.42643 - Upgrade
Upgrade
ASUS Lyra Minito a version that resolves this vulnerability.Fixed in 3.0.0.4_384_46630 - Remove
Remove
ASUS GT-AC2900from your environment.Discontinue product utilization (stop using the device) if mitigations or updates are unavailable.
- Remove
Remove
ASUS Lyra Minifrom your environment.Discontinue product utilization (stop using the device) if mitigations or updates are unavailable.
- Configuration
Disable the remote access features from WAN (disable WAN-based remote administration) to mitigate the authentication bypass.
ASUS Lyra Mini (remote access/WAN management) remote_access_from_WAN = disabled - Compensating control
Apply mitigations per vendor instructions; follow applicable BOD 22-01 guidance for cloud services; if mitigations are unavailable discontinue use of the product.
Event History
Frequently Asked Questions
What is the vulnerability ID for this ASUS GT-AC2900 vulnerability?
The vulnerability ID is CVE-2021-32030.
What is the severity of CVE-2021-32030?
The severity of CVE-2021-32030 is critical with a severity value of 9.8.
How does CVE-2021-32030 affect ASUS GT-AC2900 devices?
CVE-2021-32030 allows authentication bypass when processing remote input from an unauthenticated user, leading to unauthorized access to the administrator interface.
Which version of ASUS GT-AC2900 devices are affected by CVE-2021-32030?
ASUS GT-AC2900 devices before version 3.0.0.4.386.42643 are affected by CVE-2021-32030.
How do I fix CVE-2021-32030 on my ASUS GT-AC2900 device?
To fix CVE-2021-32030, you should update your ASUS GT-AC2900 device to version 3.0.0.4.386.42643 or later.