PT-2022-6315 · Asus · Asus Rt-Ax82U
Lilith >_>
·
Published
2022-08-01
·
Updated
2024-10-07
·
CVE-2022-35401
CVSS v3.1
9.0
Critical
| Vector | AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Asus RT-AX82U version 3.0.0.4.386 49674-ge182230
Description
An authentication bypass issue exists in the
get IFTTTTtoken.cgi functionality, allowing a specially-crafted HTTP request to lead to full administrative access to the device. An attacker would need to send a series of HTTP requests to exploit this issue. The vulnerability can be exploited by a remote attacker, potentially compromising the system.Recommendations
For Asus RT-AX82U version 3.0.0.4.386 49674-ge182230, as a temporary workaround, consider disabling the
get IFTTTTtoken.cgi functionality until a patch is available. Restrict access to the device to minimize the risk of exploitation. Avoid using the vulnerable functionality in the affected device until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this issue.Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Asus Rt-Ax82U