CVE-2022-35401: Critical severity asus rt-ax82u firmware vulnerability
An authentication bypass vulnerability exists in the getIFTTTTtoken.cgi functionality of Asus RT-AX82U 3.0.0.4.38649674-ge182230. A specially-crafted HTTP request can lead to full administrative access to the device. An attacker would need to send a series of HTTP requests to exploit this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-35401?
CVE-2022-35401 is an authentication bypass vulnerability in the get_IFTTTTtoken.cgi functionality of Asus RT-AX82U firmware version 3.0.0.4.386_49674-ge182230.
How severe is CVE-2022-35401?
CVE-2022-35401 has a severity rating of 8.1, which is considered critical.
How does CVE-2022-35401 work?
CVE-2022-35401 allows an attacker to bypass authentication and gain full administrative access to the Asus RT-AX82U device by sending a specially-crafted HTTP request.
Which versions of Asus RT-AX82U firmware are affected by CVE-2022-35401?
Asus RT-AX82U firmware version 3.0.0.4.386_49674-ge182230 is affected by CVE-2022-35401.
Is Asus RT-AX82U hardware vulnerable to CVE-2022-35401?
No, the Asus RT-AX82U hardware itself is not vulnerable to CVE-2022-35401.
How can I fix CVE-2022-35401?
To fix CVE-2022-35401, users should update their Asus RT-AX82U firmware to a version that is not affected by the vulnerability.