An HTTP response splitting attack in web application in ASUS RT-AX88U before v3.0.0.4.388.20558 allows an attacker to craft a specific URL that if an authenticated victim visits it, the URL will give access to the cloud storage of the attacker.
References
Link | Resource |
---|---|
https://github.com/efchatz/easy-exploits/tree/main/Web/ASUS/CVE-2021-41437 | Patch Third Party Advisory |
https://www.asus.com/Networking-IoT-Servers/WiFi-Routers/ASUS-Gaming-Routers/RT-AX88U/HelpDesk_BIOS/ | Patch Product Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Information
Published : 2022-09-26 07:15
Updated : 2022-09-26 21:56
NVD link : CVE-2021-41437
Mitre link : CVE-2021-41437
JSON object : View
CWE
CWE-436
Interpretation Conflict
Products Affected
asus
- rt-ax88u
- rt-ax88u_firmware