First published: Mon Sep 26 2022(Updated: )
An HTTP response splitting attack in web application in ASUS RT-AX88U before v3.0.0.4.388.20558 allows an attacker to craft a specific URL that if an authenticated victim visits it, the URL will give access to the cloud storage of the attacker.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Asus Rt-ax88u Firmware | <3.0.0.4.388.20558 | |
ASUS RT-AX88U |
https://www.asus.com/Networking-IoT-Servers/WiFi-Routers/ASUS-Gaming-Routers/RT-AX88U/HelpDesk_BIOS/
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-41437 is an HTTP response splitting attack in the web application in ASUS RT-AX88U before v3.0.0.4.388.20558 firmware, allowing an attacker to craft a specific URL to gain access to the cloud storage of the victim.
CVE-2021-41437 works by exploiting a vulnerability in the web application of ASUS RT-AX88U, where an attacker can create a malicious URL that, when visited by an authenticated victim, grants access to the attacker's cloud storage.
CVE-2021-41437 has a severity score of 6.5, which is considered medium.
ASUS RT-AX88U firmware versions before v3.0.0.4.388.20558 are affected by CVE-2021-41437.
To fix CVE-2021-41437, it is recommended to update the firmware of ASUS RT-AX88U to v3.0.0.4.388.20558 or later.