Constantinos Kolias

Researcher fromUniversity of Idaho
#5037of 53,635
52.5Total CVSS
Vulnerabilities · 7
Medium
2
High
4
Critical
1
PT-2021-23297
10
2021-11-19
Asus · Rt-Ax86 Series · CVE-2021-41435
**Name of the Vulnerable Software and Affected Versions** ASUS ROG Rapture GT-AX11000 versions prior to 3.0.0.4.386.45898 RT-AX3000 versions prior to 3.0.0.4.386.45898 RT-AX55 versions prior to 3.0.0.4.386.45898 RT-AX56U versions prior to 3.0.0.4.386.45898 RT-AX56U V2 versions prior to 3.0.0.4.386.45898 RT-AX58U versions prior to 3.0.0.4.386.45898 RT-AX82U versions prior to 3.0.0.4.386.45898 RT-AX82U GUNDAM EDITION versions prior to 3.0.0.4.386.45898 RT-AX86 Series(RT-AX86U/RT-AX86S) versions prior to 3.0.0.4.386.45898 RT-AX86U ZAKU II EDITION versions prior to 3.0.0.4.386.45898 RT-AX88U versions prior to 3.0.0.4.386.45898 RT-AX92U versions prior to 3.0.0.4.386.45898 TUF Gaming AX3000 versions prior to 3.0.0.4.386.45898 TUF Gaming AX5400 (TUF-AX5400) versions prior to 3.0.0.4.386.45898 ASUS ZenWiFi XD6 versions prior to 3.0.0.4.386.45898 ASUS ZenWiFi AX (XT8) versions prior to 3.0.0.4.386.45898 RT-AX68U versions prior to 3.0.0.4.386.45911 **Description** A brute-force protection bypass in CAPTCHA protection allows a remote attacker to attempt any number of login attempts via sending a specific HTTP request. **Recommendations** For ASUS ROG Rapture GT-AX11000, update to version 3.0.0.4.386.45898 or later. For RT-AX3000, update to version 3.0.0.4.386.45898 or later. For RT-AX55, update to version 3.0.0.4.386.45898 or later. For RT-AX56U, update to version 3.0.0.4.386.45898 or later. For RT-AX56U V2, update to version 3.0.0.4.386.45898 or later. For RT-AX58U, update to version 3.0.0.4.386.45898 or later. For RT-AX82U, update to version 3.0.0.4.386.45898 or later. For RT-AX82U GUNDAM EDITION, update to version 3.0.0.4.386.45898 or later. For RT-AX86 Series(RT-AX86U/RT-AX86S), update to version 3.0.0.4.386.45898 or later. For RT-AX86U ZAKU II EDITION, update to version 3.0.0.4.386.45898 or later. For RT-AX88U, update to version 3.0.0.4.386.45898 or later. For RT-AX92U, update to version 3.0.0.4.386.45898 or later. For TUF Gaming AX3000, update to version 3.0.0.4.386.45898 or later. For TUF Gaming AX5400 (TUF-AX5400), update to version 3.0.0.4.386.45898 or later. For ASUS ZenWiFi XD6, update to version 3.0.0.4.386.45898 or later. For ASUS ZenWiFi AX (XT8), update to version 3.0.0.4.386.45898 or later. For RT-AX68U, update to version 3.0.0.4.386.45911 or later.
PT-2021-23298
7.8
2021-11-19
Asus · Rt-Ax86 Series · CVE-2021-41436
**Name of the Vulnerable Software and Affected Versions** ASUS ROG Rapture GT-AX11000 versions prior to 3.0.0.4.386.45898 RT-AX3000 versions prior to 3.0.0.4.386.45898 RT-AX55 versions prior to 3.0.0.4.386.45898 RT-AX56U versions prior to 3.0.0.4.386.45898 RT-AX56U V2 versions prior to 3.0.0.4.386.45898 RT-AX58U versions prior to 3.0.0.4.386.45898 RT-AX82U versions prior to 3.0.0.4.386.45898 RT-AX82U GUNDAM EDITION versions prior to 3.0.0.4.386.45898 RT-AX86 Series (RT-AX86U/RT-AX86S) versions prior to 3.0.0.4.386.45898 RT-AX86U ZAKU II EDITION versions prior to 3.0.0.4.386.45898 RT-AX88U versions prior to 3.0.0.4.386.45898 RT-AX92U versions prior to 3.0.0.4.386.45898 TUF Gaming AX3000 versions prior to 3.0.0.4.386.45898 TUF Gaming AX5400 (TUF-AX5400) versions prior to 3.0.0.4.386.45898 ASUS ZenWiFi XD6 versions prior to 3.0.0.4.386.45898 ASUS ZenWiFi AX (XT8) versions prior to 3.0.0.4.386.45898 RT-AX68U versions prior to 3.0.0.4.386.45911 **Description** The issue is related to HTTP request smuggling in the web application of the affected devices, allowing a remote unauthenticated attacker to perform a denial-of-service (DoS) attack via sending a specially crafted HTTP packet. **Recommendations** ASUS ROG Rapture GT-AX11000: Update to version 3.0.0.4.386.45898 or later. RT-AX3000: Update to version 3.0.0.4.386.45898 or later. RT-AX55: Update to version 3.0.0.4.386.45898 or later. RT-AX56U: Update to version 3.0.0.4.386.45898 or later. RT-AX56U V2: Update to version 3.0.0.4.386.45898 or later. RT-AX58U: Update to version 3.0.0.4.386.45898 or later. RT-AX82U: Update to version 3.0.0.4.386.45898 or later. RT-AX82U GUNDAM EDITION: Update to version 3.0.0.4.386.45898 or later. RT-AX86 Series (RT-AX86U/RT-AX86S): Update to version 3.0.0.4.386.45898 or later. RT-AX86U ZAKU II EDITION: Update to version 3.0.0.4.386.45898 or later. RT-AX88U: Update to version 3.0.0.4.386.45898 or later. RT-AX92U: Update to version 3.0.0.4.386.45898 or later. TUF Gaming AX3000: Update to version 3.0.0.4.386.45898 or later. TUF Gaming AX5400 (TUF-AX5400): Update to version 3.0.0.4.386.45898 or later. ASUS ZenWiFi XD6: Update to version 3.0.0.4.386.45898 or later. ASUS ZenWiFi AX (XT8): Update to version 3.0.0.4.386.45898 or later. RT-AX68U: Update to version 3.0.0.4.386.45911 or later.