CVE-2021-41437

Severity CVSS v4.0:
Pending analysis
Type:
CWE-74 Injection
Publication date:
26/09/2022
Last modified:
21/05/2025

Description

An HTTP response splitting attack in web application in ASUS RT-AX88U before v3.0.0.4.388.20558 allows an attacker to craft a specific URL that if an authenticated victim visits it, the URL will give access to the cloud storage of the attacker.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:asus:rt-ax88u_firmware:*:*:*:*:*:*:*:* 3.0.0.4.388.20558 (excluding)
cpe:2.3:h:asus:rt-ax88u:-:*:*:*:*:*:*:*