CVE-2021-3128

HIGHCVSS 7.5/10EPSS 2.18%

Last modified

CVE-2021-3128 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. In ASUS RT-AX3000, ZenWiFi AX (XT8), RT-AX88U, and other ASUS routers with firmware < 3.0.0.4.386.42095 or < 9.0.0.4.386.41994, when IPv6 is used, a routing loop can occur that generates excessive network traffic between an affected device and its upstream ISP's router. This occurs when a link prefix route points to a point-to-point link, a destination IPv6 address belongs to the prefix and is not a local IPv6 address, and a router advertisement is received with at least one global unique IPv6 prefix for which the on-link flag is set.. EPSS estimates a 2.18% chance of exploitation in the next 30 days.

Description

In ASUS RT-AX3000, ZenWiFi AX (XT8), RT-AX88U, and other ASUS routers with firmware < 3.0.0.4.386.42095 or < 9.0.0.4.386.41994, when IPv6 is used, a routing loop can occur that generates excessive network traffic between an affected device and its upstream ISP's router. This occurs when a link prefix route points to a point-to-point link, a destination IPv6 address belongs to the prefix and is not a local IPv6 address, and a router advertisement is received with at least one global unique IPv6 prefix for which the on-link flag is set.

Metrics

CVSS 3.1
7.5/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS Probability
2.18%

80.1th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
AsusZenwifi Ax \(Xt8\) Firmware< 3.0.0.4.386.42095
AsusZenwifi Ax \(Xt8\) Firmware< 9.0.0.4.386.41994
AsusRt-Ax3000 Firmware< 3.0.0.4.386.42095
AsusRt-Ax3000 Firmware< 9.0.0.4.386.41994
AsusRt-Ax55 Firmware< 3.0.0.4.386.42095
AsusRt-Ax55 Firmware< 9.0.0.4.386.41994
AsusRt-Ax56u Firmware< 3.0.0.4.386.42095
AsusRt-Ax56u Firmware< 9.0.0.4.386.41994
AsusRt-Ax58u Firmware< 3.0.0.4.386.42095
AsusRt-Ax58u Firmware< 9.0.0.4.386.41994
AsusRt-Ax68u Firmware< 3.0.0.4.386.42095
AsusRt-Ax68u Firmware< 9.0.0.4.386.41994
AsusRt-Ax82u Firmware< 3.0.0.4.386.42095
AsusRt-Ax82u Firmware< 9.0.0.4.386.41994
AsusRt-Ax86u Firmware< 3.0.0.4.386.42095
AsusRt-Ax86u Firmware< 9.0.0.4.386.41994
AsusRt-Ax88u Firmware< 3.0.0.4.386.42095
AsusRt-Ax88u Firmware< 9.0.0.4.386.41994
AsusRt-Ac66u B1 Firmware< 3.0.0.4.386.42095
AsusRt-Ac66u B1 Firmware< 9.0.0.4.386.41994
AsusRt-Ac1750 B1 Firmware< 3.0.0.4.386.42095
AsusRt-Ac1750 B1 Firmware< 9.0.0.4.386.41994
AsusRt-Ac1900 Firmware< 3.0.0.4.386.42095
AsusRt-Ac1900 Firmware< 9.0.0.4.386.41994
AsusRt-Ac1900p Firmware< 3.0.0.4.386.42095
AsusRt-Ac1900p Firmware< 9.0.0.4.386.41994
AsusRt-Ac1900u Firmware< 3.0.0.4.386.42095
AsusRt-Ac1900u Firmware< 9.0.0.4.386.41994
AsusRt-Ac2900 Firmware< 3.0.0.4.386.42095
AsusRt-Ac2900 Firmware< 9.0.0.4.386.41994
AsusRt-Ac3100 Firmware< 3.0.0.4.386.42095
AsusRt-Ac3100 Firmware< 9.0.0.4.386.41994
AsusRt-Ac5300 Firmware< 3.0.0.4.386.42095
AsusRt-Ac5300 Firmware< 9.0.0.4.386.41994
AsusRt-Ac58u Firmware< 3.0.0.4.386.42095
AsusRt-Ac58u Firmware< 9.0.0.4.386.41994
AsusRt-Ac65u Firmware< 3.0.0.4.386.42095
AsusRt-Ac65u Firmware< 9.0.0.4.386.41994
AsusRt-Ac68p Firmware< 3.0.0.4.386.42095
AsusRt-Ac68p Firmware< 9.0.0.4.386.41994
AsusRt-Ac68r Firmware< 3.0.0.4.386.42095
AsusRt-Ac68r Firmware< 9.0.0.4.386.41994
AsusRt-Ac68rw Firmware< 3.0.0.4.386.42095
AsusRt-Ac68rw Firmware< 9.0.0.4.386.41994
AsusRt-Ac68u Firmware< 3.0.0.4.386.42095
AsusRt-Ac68u Firmware< 9.0.0.4.386.41994
AsusRt-Ac68w Firmware< 3.0.0.4.386.42095
AsusRt-Ac68w Firmware< 9.0.0.4.386.41994
AsusRt-Ac85u Firmware< 3.0.0.4.386.42095
AsusRt-Ac85u Firmware< 9.0.0.4.386.41994

Showing 50 of 54 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2021-3128?
In ASUS RT-AX3000, ZenWiFi AX (XT8), RT-AX88U, and other ASUS routers with firmware < 3.0.0.4.386.42095 or < 9.0.0.4.386.41994, when IPv6 is used, a routing loop can occur that generates excessive network traffic between an affected device and its upstream ISP's router. This occurs when a link prefix route points to a point-to-point link, a destination IPv6 address belongs to the prefix and is not a local IPv6 address, and a router advertisement is received with at least one global unique IPv6 prefix for which the on-link flag is set.
How severe is CVE-2021-3128?
CVE-2021-3128 has a CVSS score of 7.5/10 (HIGH severity). The EPSS model estimates a 2.18% probability of exploitation in the next 30 days.
How do I fix CVE-2021-3128?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2021-3128?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST