PT-2021-19636 · Asus · Asus Lyra Mini+1

Chris Bellows

+1

·

Published

2021-05-06

·

Updated

2025-11-10

·

CVE-2021-32030

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ASUS GT-AC2900 versions prior to 3.0.0.4.386.42643 Lyra Mini versions prior to 3.0.0.4 384 46630
Description The administrator application on ASUS GT-AC2900 and Lyra Mini devices allows authentication bypass when processing remote input from an unauthenticated user, leading to unauthorized access to the administrator interface. This issue relates to the handle request function in router/httpd/httpd.c and auth check in web hook.o. An attacker-supplied value of 0 matches the device's default value of 0 in some situations. There have been attempts to exploit this issue, with 379,868 attempts reported as failed due to a tiny error.
Recommendations For ASUS GT-AC2900 versions prior to 3.0.0.4.386.42643, update to version 3.0.0.4.386.42643 or later. For Lyra Mini versions prior to 3.0.0.4 384 46630, update to version 3.0.0.4 384 46630 or later. As a temporary workaround, consider disabling the remote access features from WAN to minimize the risk of exploitation.

Exploit

Fix

Improper Authentication

Weakness Enumeration

Related Identifiers

BDU:2025-06519
CVE-2021-32030

Affected Products

Asus Rt-Ac2900
Asus Lyra Mini