PT-2022-11403 · Asus · Asus Rt-Ax88U

Published

2022-09-26

·

Updated

2023-08-08

·

CVE-2021-41437

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions ASUS RT-AX88U versions prior to 3.0.0.4.388.20558
Description The issue allows an attacker to perform an HTTP response splitting attack, enabling them to craft a specific URL. If an authenticated victim visits this URL, it grants the attacker access to their cloud storage.
Recommendations For versions prior to 3.0.0.4.388.20558, update to version 3.0.0.4.388.20558 or later to resolve the issue.

Exploit

Fix

Special Elements Injection

Weakness Enumeration

Related Identifiers

CVE-2021-41437

Affected Products

Asus Rt-Ax88U