A brute-force protection bypass in CAPTCHA protection in ASUS ROG Rapture GT-AX11000, RT-AX3000, RT-AX55, RT-AX56U, RT-AX56U_V2, RT-AX58U, RT-AX82U, RT-AX82U GUNDAM EDITION, RT-AX86 Series(RT-AX86U/RT-AX86S), RT-AX86U ZAKU II EDITION, RT-AX88U, RT-AX92U, TUF Gaming AX3000, TUF Gaming AX5400 (TUF-AX5400), ASUS ZenWiFi XD6, ASUS ZenWiFi AX (XT8) before 3.0.0.4.386.45898, and RT-AX68U before 3.0.0.4.386.45911, allows a remote attacker to attempt any number of login attempts via sending a specific HTTP request.

Project Subscriptions

Vendors Products
Gt-ax11000 Subscribe
Gt-ax11000 Firmware Subscribe
Rt-ax3000 Subscribe
Rt-ax3000 Firmware Subscribe
Rt-ax55 Subscribe
Rt-ax55 Firmware Subscribe
Rt-ax56u Subscribe
Rt-ax56u Firmware Subscribe
Rt-ax56u V2 Subscribe
Rt-ax56u V2 Firmware Subscribe
Rt-ax58u Subscribe
Rt-ax58u Firmware Subscribe
Rt-ax68u Subscribe
Rt-ax68u Firmware Subscribe
Rt-ax82u Subscribe
Rt-ax82u Firmware Subscribe
Rt-ax82u Gundam Edition Subscribe
Rt-ax82u Gundam Edition Firmware Subscribe
Rt-ax86s Subscribe
Rt-ax86s Firmware Subscribe
Rt-ax86u Subscribe
Rt-ax86u Firmware Subscribe
Rt-ax86u Zaku Ii Edition Subscribe
Rt-ax86u Zaku Ii Edition Firmware Subscribe
Rt-ax88u Subscribe
Rt-ax88u Firmware Subscribe
Rt-ax92u Subscribe
Rt-ax92u Firmware Subscribe
Tuf-ax5400 Subscribe
Tuf-ax5400 Firmware Subscribe
Tuf Gaming Ax3000 Subscribe
Tuf Gaming Ax3000 Firmware Subscribe
Zenwifi Ax \(xt8\) Subscribe
Zenwifi Ax \(xt8\) Firmware Subscribe
Zenwifi Xd6 Subscribe
Zenwifi Xd6 Firmware Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2021-28462 A brute-force protection bypass in CAPTCHA protection in ASUS ROG Rapture GT-AX11000, RT-AX3000, RT-AX55, RT-AX56U, RT-AX56U_V2, RT-AX58U, RT-AX82U, RT-AX82U GUNDAM EDITION, RT-AX86 Series(RT-AX86U/RT-AX86S), RT-AX86U ZAKU II EDITION, RT-AX88U, RT-AX92U, TUF Gaming AX3000, TUF Gaming AX5400 (TUF-AX5400), ASUS ZenWiFi XD6, ASUS ZenWiFi AX (XT8) before 3.0.0.4.386.45898, and RT-AX68U before 3.0.0.4.386.45911, allows a remote attacker to attempt any number of login attempts via sending a specific HTTP request.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-04T03:15:27.279Z

Reserved: 2021-09-20T00:00:00

Link: CVE-2021-41435

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-11-19T12:15:09.330

Modified: 2024-11-21T06:26:14.863

Link: CVE-2021-41435

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses