CVE-2021-41435Critical· 9.8▾ MidnightA brute-force protection bypass in CAPTCHA protection in ASUS ROG Rapture GT-AX11000, RT-AX3000, RT-AX55, RT-AX56U, RT-AX56U_V2, RT-AX58U, RT-AX82U, RT-AX82U GUNDAM EDITION, RT-AX86 Series(RT-AX86U/RT-AX86S), RT-AX86U ZAKU II EDITION, RT…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 53.9 · likelihood 1.3 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 6.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
6.0%
6.0% → 6.5%
A brute-force protection bypass in CAPTCHA protection in ASUS ROG Rapture GT-AX11000, RT-AX3000, RT-AX55, RT-AX56U, RT-AX56U_V2, RT-AX58U, RT-AX82U, RT-AX82U GUNDAM EDITION, RT-AX86 Series(RT-AX86U/RT-AX86S), RT-AX86U ZAKU II EDITION, RT-AX88U, RT-AX92U, TUF Gaming AX3000, TUF Gaming AX5400 (TUF-AX5400), ASUS ZenWiFi XD6, ASUS ZenWiFi AX (XT8) before 3.0.0.4.386.45898, and RT-AX68U before 3.0.0.4.386.45911, allows a remote attacker to attempt any number of login attempts via sending a specific HTTP request.
gt-ax11000_firmware < 3.0.0.4.386.45898rt-ax3000_firmware < 3.0.0.4.386.45898rt-ax55_firmware < 3.0.0.4.386.45898rt-ax56u_firmware < 3.0.0.4.386.45898rt-ax56u_v2_firmware < 3.0.0.4.386.45898rt-ax58u_firmware < 3.0.0.4.386.45898rt-ax82u_firmware < 3.0.0.4.386.45898rt-ax82u_gundam_edition_firmware < 3.0.0.4.386.45898rt-ax86u_firmware < 3.0.0.4.386.45898rt-ax86s_firmware < 3.0.0.4.386.45898rt-ax86u_zaku_ii_edition_firmware < 3.0.0.4.386.45898rt-ax88u_firmware < 3.0.0.4.386.45898rt-ax92u_firmware < 3.0.0.4.386.45898tuf_gaming_ax3000_firmware < 3.0.0.4.386.45898tuf-ax5400_firmware < 3.0.0.4.386.45898zenwifi_xd6_firmware < 3.0.0.4.386.45898zenwifi_ax_(xt8)_firmware < 3.0.0.4.386.45898rt-ax68u_firmware < 3.0.0.4.386.45911Upgrade past the affected range:
gt-ax11000_firmware 3.0.0.4.386.45898rt-ax3000_firmware 3.0.0.4.386.45898rt-ax55_firmware 3.0.0.4.386.45898rt-ax56u_firmware 3.0.0.4.386.45898rt-ax56u_v2_firmware 3.0.0.4.386.45898rt-ax58u_firmware 3.0.0.4.386.45898rt-ax82u_firmware 3.0.0.4.386.45898rt-ax82u_gundam_edition_firmware 3.0.0.4.386.45898rt-ax86u_firmware 3.0.0.4.386.45898rt-ax86s_firmware 3.0.0.4.386.45898rt-ax86u_zaku_ii_edition_firmware 3.0.0.4.386.45898rt-ax88u_firmware 3.0.0.4.386.45898rt-ax92u_firmware 3.0.0.4.386.45898tuf_gaming_ax3000_firmware 3.0.0.4.386.45898tuf-ax5400_firmware 3.0.0.4.386.45898zenwifi_xd6_firmware 3.0.0.4.386.45898zenwifi_ax_(xt8)_firmware 3.0.0.4.386.45898rt-ax68u_firmware 3.0.0.4.386.45911Connected by shared product, vendor, weakness, or advisory.
CVE-2021-41436High· 7.5An HTTP request smuggling in web application in ASUS ROG Rapture GT-AX11000, RT-AX3000, RT-AX55, RT-AX56U, RT-AX56U_V2, RT-AX58U, RT-AX82U, RT-AX82U GUNDAM EDITION, RT-AX86 Series(RT-AX86U/RT-AX86S), RT-AX86U ZAKU II EDITION, RT-AX88U, R…
CVE-2021-45757High· 7.5ASUS AC68U <=3.0.0.4.385.20852 is affected by a buffer overflow in blocking.cgi, which may cause a denial of service (DoS).
CVE-2021-45756Critical· 9.8Asus RT-AC68U <3.0.0.4.385.20633 and RT-AC5300 <3.0.0.4.384.82072 are affected by a buffer overflow in blocking_request.cgi.
CVE-2026-8070High· 7.3Incorrect permission assignment for a critical resource in Armoury Crate allows a local user to bypass the driver’s validation mechanism, resulting in unauthorized read and write access to physical memory.Refer to the ' Security Update …
CVE-2026-6737Low· 2.0An Exposed IOCTL with Insufficient Access Control vulnerability in AsusPTPFilter allows a local user to bypass driver security mechanisms and obtain restricted touchpad information or render the touchpad unusable via crafted IOCTL reques…
CVE-2026-1880Medium· 5.4An Incorrect Permission Assignment for Critical Resource vulnerability in the ASUS DriverHub update process allows privilege escalation due to improper protection of required execution resources during the validation phase, permitting a …