A brute-force protection bypass in CAPTCHA protection in ASUS ROG Rapture GT-AX11000, RT-AX3000, RT-AX55, RT-AX56U, RT-AX56U_V2, RT-AX58U, RT-AX82U, RT-AX82U GUNDAM EDITION, RT-AX86 Series(RT-AX86U/RT-AX86S), RT-AX86U ZAKU II EDITION, RT-AX88U, RT-AX92U, TUF Gaming AX3000, TUF Gaming AX5400 (TUF-AX5400), ASUS ZenWiFi XD6, ASUS ZenWiFi AX (XT8) before 3.0.0.4.386.45898, and RT-AX68U before 3.0.0.4.386.45911, allows a remote attacker to attempt any number of login attempts via sending a specific HTTP request.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Asus
Subscribe
|
Gt-ax11000
Subscribe
Gt-ax11000 Firmware
Subscribe
Rt-ax3000
Subscribe
Rt-ax3000 Firmware
Subscribe
Rt-ax55
Subscribe
Rt-ax55 Firmware
Subscribe
Rt-ax56u
Subscribe
Rt-ax56u Firmware
Subscribe
Rt-ax56u V2
Subscribe
Rt-ax56u V2 Firmware
Subscribe
Rt-ax58u
Subscribe
Rt-ax58u Firmware
Subscribe
Rt-ax68u
Subscribe
Rt-ax68u Firmware
Subscribe
Rt-ax82u
Subscribe
Rt-ax82u Firmware
Subscribe
Rt-ax82u Gundam Edition
Subscribe
Rt-ax82u Gundam Edition Firmware
Subscribe
Rt-ax86s
Subscribe
Rt-ax86s Firmware
Subscribe
Rt-ax86u
Subscribe
Rt-ax86u Firmware
Subscribe
Rt-ax86u Zaku Ii Edition
Subscribe
Rt-ax86u Zaku Ii Edition Firmware
Subscribe
Rt-ax88u
Subscribe
Rt-ax88u Firmware
Subscribe
Rt-ax92u
Subscribe
Rt-ax92u Firmware
Subscribe
Tuf-ax5400
Subscribe
Tuf-ax5400 Firmware
Subscribe
Tuf Gaming Ax3000
Subscribe
Tuf Gaming Ax3000 Firmware
Subscribe
Zenwifi Ax \(xt8\)
Subscribe
Zenwifi Ax \(xt8\) Firmware
Subscribe
Zenwifi Xd6
Subscribe
Zenwifi Xd6 Firmware
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-28462 | A brute-force protection bypass in CAPTCHA protection in ASUS ROG Rapture GT-AX11000, RT-AX3000, RT-AX55, RT-AX56U, RT-AX56U_V2, RT-AX58U, RT-AX82U, RT-AX82U GUNDAM EDITION, RT-AX86 Series(RT-AX86U/RT-AX86S), RT-AX86U ZAKU II EDITION, RT-AX88U, RT-AX92U, TUF Gaming AX3000, TUF Gaming AX5400 (TUF-AX5400), ASUS ZenWiFi XD6, ASUS ZenWiFi AX (XT8) before 3.0.0.4.386.45898, and RT-AX68U before 3.0.0.4.386.45911, allows a remote attacker to attempt any number of login attempts via sending a specific HTTP request. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T03:15:27.279Z
Reserved: 2021-09-20T00:00:00
Link: CVE-2021-41435
No data.
Status : Modified
Published: 2021-11-19T12:15:09.330
Modified: 2024-11-21T06:26:14.863
Link: CVE-2021-41435
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD