An HTTP response splitting attack in web application in ASUS RT-AX88U before v3.0.0.4.388.20558 allows an attacker to craft a specific URL that if an authenticated victim visits it, the URL will give access to the cloud storage of the attacker.
References
Link | Resource |
---|---|
https://github.com/efchatz/easy-exploits/tree/main/Web/ASUS/CVE-2021-41437 | Patch Third Party Advisory |
https://www.asus.com/Networking-IoT-Servers/WiFi-Routers/ASUS-Gaming-Routers/RT-AX88U/HelpDesk_BIOS/ | Patch Product Vendor Advisory |
https://github.com/efchatz/easy-exploits/tree/main/Web/ASUS/CVE-2021-41437 | Patch Third Party Advisory |
https://www.asus.com/Networking-IoT-Servers/WiFi-Routers/ASUS-Gaming-Routers/RT-AX88U/HelpDesk_BIOS/ | Patch Product Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
History
21 Nov 2024, 06:26
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/efchatz/easy-exploits/tree/main/Web/ASUS/CVE-2021-41437 - Patch, Third Party Advisory | |
References | () https://www.asus.com/Networking-IoT-Servers/WiFi-Routers/ASUS-Gaming-Routers/RT-AX88U/HelpDesk_BIOS/ - Patch, Product, Vendor Advisory |
08 Aug 2023, 14:21
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-74 |
Information
Published : 2022-09-26 14:15
Updated : 2024-11-21 06:26
NVD link : CVE-2021-41437
Mitre link : CVE-2021-41437
CVE.ORG link : CVE-2021-41437
JSON object : View
Products Affected
asus
- rt-ax88u
- rt-ax88u_firmware
CWE
CWE-74
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')