CVE-2021-41436High· 7.5▾ TwilightAn HTTP request smuggling in web application in ASUS ROG Rapture GT-AX11000, RT-AX3000, RT-AX55, RT-AX56U, RT-AX56U_V2, RT-AX58U, RT-AX82U, RT-AX82U GUNDAM EDITION, RT-AX86 Series(RT-AX86U/RT-AX86S), RT-AX86U ZAKU II EDITION, RT-AX88U, R…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 6.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
4.6%
4.6% → 5.0%
An HTTP request smuggling in web application in ASUS ROG Rapture GT-AX11000, RT-AX3000, RT-AX55, RT-AX56U, RT-AX56U_V2, RT-AX58U, RT-AX82U, RT-AX82U GUNDAM EDITION, RT-AX86 Series(RT-AX86U/RT-AX86S), RT-AX86U ZAKU II EDITION, RT-AX88U, RT-AX92U, TUF Gaming AX3000, TUF Gaming AX5400 (TUF-AX5400), ASUS ZenWiFi XD6, ASUS ZenWiFi AX (XT8) before 3.0.0.4.386.45898, and RT-AX68U before 3.0.0.4.386.45911, allows a remote unauthenticated attacker to DoS via sending a specially crafted HTTP packet.
gt-ax11000_firmware < 3.0.0.4.386.45898rt-ax3000_firmware < 3.0.0.4.386.45898rt-ax55_firmware < 3.0.0.4.386.45898rt-ax56u_firmware < 3.0.0.4.386.45898rt-ax56u_v2_firmware < 3.0.0.4.386.45898rt-ax58u_firmware < 3.0.0.4.386.45898rt-ax82u_firmware < 3.0.0.4.386.45898rt-ax82u_gundam_edition_firmware < 3.0.0.4.386.45898rt-ax86u_firmware < 3.0.0.4.386.45898rt-ax86s_firmware < 3.0.0.4.386.45898rt-ax86u_zaku_ii_edition_firmware < 3.0.0.4.386.45898rt-ax88u_firmware < 3.0.0.4.386.45898rt-ax92u_firmware < 3.0.0.4.386.45898tuf_gaming_ax3000_firmware < 3.0.0.4.386.45898tuf-ax5400_firmware < 3.0.0.4.386.45898zenwifi_xd6_firmware < 3.0.0.4.386.45898zenwifi_ax_(xt8)_firmware < 3.0.0.4.386.45898rt-ax68u_firmware < 3.0.0.4.386.45911Upgrade past the affected range:
gt-ax11000_firmware 3.0.0.4.386.45898rt-ax3000_firmware 3.0.0.4.386.45898rt-ax55_firmware 3.0.0.4.386.45898rt-ax56u_firmware 3.0.0.4.386.45898rt-ax56u_v2_firmware 3.0.0.4.386.45898rt-ax58u_firmware 3.0.0.4.386.45898rt-ax82u_firmware 3.0.0.4.386.45898rt-ax82u_gundam_edition_firmware 3.0.0.4.386.45898rt-ax86u_firmware 3.0.0.4.386.45898rt-ax86s_firmware 3.0.0.4.386.45898rt-ax86u_zaku_ii_edition_firmware 3.0.0.4.386.45898rt-ax88u_firmware 3.0.0.4.386.45898rt-ax92u_firmware 3.0.0.4.386.45898tuf_gaming_ax3000_firmware 3.0.0.4.386.45898tuf-ax5400_firmware 3.0.0.4.386.45898zenwifi_xd6_firmware 3.0.0.4.386.45898zenwifi_ax_(xt8)_firmware 3.0.0.4.386.45898rt-ax68u_firmware 3.0.0.4.386.45911Connected by shared product, vendor, weakness, or advisory.
CVE-2021-41435Critical· 9.8A brute-force protection bypass in CAPTCHA protection in ASUS ROG Rapture GT-AX11000, RT-AX3000, RT-AX55, RT-AX56U, RT-AX56U_V2, RT-AX58U, RT-AX82U, RT-AX82U GUNDAM EDITION, RT-AX86 Series(RT-AX86U/RT-AX86S), RT-AX86U ZAKU II EDITION, RT…
CVE-2021-45757High· 7.5ASUS AC68U <=3.0.0.4.385.20852 is affected by a buffer overflow in blocking.cgi, which may cause a denial of service (DoS).
CVE-2021-45756Critical· 9.8Asus RT-AC68U <3.0.0.4.385.20633 and RT-AC5300 <3.0.0.4.384.82072 are affected by a buffer overflow in blocking_request.cgi.
CVE-2021-33037Medium· 5.3Apache Tomcat 10.0.0-M1 to 10.0.6, 9.0.0.M1 to 9.0.46 and 8.5.0 to 8.5.66 did not correctly parse the HTTP transfer-encoding request header in some circumstances leading to the possibility to request smuggling when used with a reverse pr…
CVE-2023-41265Critical· 9.6An HTTP Request Tunneling vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7 and earlier, November 2022 Patch 10 and earlier, and August 2022 Patch 12 and earlier all…
CVE-2026-8070High· 7.3Incorrect permission assignment for a critical resource in Armoury Crate allows a local user to bypass the driver’s validation mechanism, resulting in unauthorized read and write access to physical memory.Refer to the ' Security Update …