CVE-2021-41437

An HTTP response splitting attack in web application in ASUS RT-AX88U before v3.0.0.4.388.20558 allows an attacker to craft a specific URL that if an authenticated victim visits it, the URL will give access to the cloud storage of the attacker.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:asus:rt-ax88u_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:asus:rt-ax88u:-:*:*:*:*:*:*:*

History

21 Nov 2024, 06:26

Type Values Removed Values Added
References () https://github.com/efchatz/easy-exploits/tree/main/Web/ASUS/CVE-2021-41437 - Patch, Third Party Advisory () https://github.com/efchatz/easy-exploits/tree/main/Web/ASUS/CVE-2021-41437 - Patch, Third Party Advisory
References () https://www.asus.com/Networking-IoT-Servers/WiFi-Routers/ASUS-Gaming-Routers/RT-AX88U/HelpDesk_BIOS/ - Patch, Product, Vendor Advisory () https://www.asus.com/Networking-IoT-Servers/WiFi-Routers/ASUS-Gaming-Routers/RT-AX88U/HelpDesk_BIOS/ - Patch, Product, Vendor Advisory

08 Aug 2023, 14:21

Type Values Removed Values Added
CWE CWE-436 CWE-74

Information

Published : 2022-09-26 14:15

Updated : 2024-11-21 06:26


NVD link : CVE-2021-41437

Mitre link : CVE-2021-41437

CVE.ORG link : CVE-2021-41437


JSON object : View

Products Affected

asus

  • rt-ax88u
  • rt-ax88u_firmware
CWE
CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')