HTTP Response Splitting Vulnerability in ASUS RT-AX88U Router
CVE-2021-41437
6.5MEDIUM
Key Information:
- Vendor
Asus
- Status
- Vendor
- CVE Published:
- 26 September 2022
Badges
👾 Exploit Exists🟡 Public PoC
What is CVE-2021-41437?
The ASUS RT-AX88U router is vulnerable to an HTTP response splitting attack, allowing unauthorized access to an attacker's cloud storage. By crafting a specific URL, an authenticated user can inadvertently expose their data to malicious actors, thus compromising the integrity and confidentiality of sensitive information. This vulnerability affects all versions prior to v3.0.0.4.388.20558, emphasizing the need for users to update their firmware promptly to mitigate risks.
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.