PT-2021-19636 · Asus · Asus Lyra Mini+1
Chris Bellows
+1
·
Published
2021-05-06
·
Updated
2025-11-10
·
CVE-2021-32030
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
ASUS GT-AC2900 versions prior to 3.0.0.4.386.42643
Lyra Mini versions prior to 3.0.0.4 384 46630
Description
The administrator application on ASUS GT-AC2900 and Lyra Mini devices allows authentication bypass when processing remote input from an unauthenticated user, leading to unauthorized access to the administrator interface. This issue relates to the
handle request function in router/httpd/httpd.c and auth check in web hook.o. An attacker-supplied value of 0 matches the device's default value of 0 in some situations. There have been attempts to exploit this issue, with 379,868 attempts reported as failed due to a tiny error.Recommendations
For ASUS GT-AC2900 versions prior to 3.0.0.4.386.42643, update to version 3.0.0.4.386.42643 or later.
For Lyra Mini versions prior to 3.0.0.4 384 46630, update to version 3.0.0.4 384 46630 or later.
As a temporary workaround, consider disabling the remote access features from WAN to minimize the risk of exploitation.
Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Asus Rt-Ac2900
Asus Lyra Mini