CVE-2021-41435: Critical severity ASUS Gt-ax11000 Firmware vulnerability
A brute-force protection bypass in CAPTCHA protection in ASUS ROG Rapture GT-AX11000, RT-AX3000, RT-AX55, RT-AX56U, RT-AX56UV2, RT-AX58U, RT-AX82U, RT-AX82U GUNDAM EDITION, RT-AX86 Series(RT-AX86U/RT-AX86S), RT-AX86U ZAKU II EDITION, RT-AX88U, RT-AX92U, TUF Gaming AX3000, TUF Gaming AX5400 (TUF-AX5400), ASUS ZenWiFi XD6, ASUS ZenWiFi AX (XT8) before 3.0.0.4.386.45898, and RT-AX68U before 3.0.0.4.386.45911, allows a remote attacker to attempt any number of login attempts via sending a specific HTTP request.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-41435?
CVE-2021-41435 has a medium severity rating due to its potential for brute-force protection bypass.
How do I fix CVE-2021-41435?
To fix CVE-2021-41435, update your affected ASUS router firmware to the latest version available on the ASUS support website.
Which ASUS devices are affected by CVE-2021-41435?
CVE-2021-41435 affects multiple ASUS routers including ROG Rapture GT-AX11000 and RT-AX3000, among others.
Is there a way to mitigate CVE-2021-41435 if I cannot update my firmware?
If you cannot update your firmware, consider disabling remote access and using strong, unique passwords to mitigate the risks associated with CVE-2021-41435.
Who should be concerned about CVE-2021-41435?
Users of the affected ASUS routers should be concerned about CVE-2021-41435, especially if their devices are exposed to the internet.