CVE-2021-41436: High severity ASUS Gt-ax11000 Firmware vulnerability
An HTTP request smuggling in web application in ASUS ROG Rapture GT-AX11000, RT-AX3000, RT-AX55, RT-AX56U, RT-AX56UV2, RT-AX58U, RT-AX82U, RT-AX82U GUNDAM EDITION, RT-AX86 Series(RT-AX86U/RT-AX86S), RT-AX86U ZAKU II EDITION, RT-AX88U, RT-AX92U, TUF Gaming AX3000, TUF Gaming AX5400 (TUF-AX5400), ASUS ZenWiFi XD6, ASUS ZenWiFi AX (XT8) before 3.0.0.4.386.45898, and RT-AX68U before 3.0.0.4.386.45911, allows a remote unauthenticated attacker to DoS via sending a specially crafted HTTP packet.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-41436?
CVE-2021-41436 is classified as a high severity vulnerability due to its potential to allow HTTP request smuggling in affected ASUS routers.
How do I fix CVE-2021-41436?
To fix CVE-2021-41436, update your affected ASUS router firmware to the latest version provided by ASUS.
Which ASUS models are affected by CVE-2021-41436?
CVE-2021-41436 affects multiple ASUS routers including the GT-AX11000, RT-AX3000, RT-AX55, and several others.
What is HTTP request smuggling and how does it relate to CVE-2021-41436?
HTTP request smuggling is a technique that exploits discrepancies in the interpretation of HTTP requests between different servers or proxies, which is the issue exploited by CVE-2021-41436.
What symptoms might indicate an exploitation of CVE-2021-41436?
Symptoms of exploitation of CVE-2021-41436 may include unusual router behavior, unexpected logs, or unauthorized access attempts.