CVE-2021-43702
Last modified
CVE-2021-43702 is a critical-severity vulnerability rated 9/10 on the CVSS scale. ASUS RT-A88U 3.0.0.4.386_45898 is vulnerable to Cross Site Scripting (XSS). The ASUS router admin panel does not sanitize the WiFI logs correctly, if an attacker was able to change the SSID of the router with a custom payload, they could achieve stored XSS on the device.. EPSS estimates a 0.83% chance of exploitation in the next 30 days.
Description
ASUS RT-A88U 3.0.0.4.386_45898 is vulnerable to Cross Site Scripting (XSS). The ASUS router admin panel does not sanitize the WiFI logs correctly, if an attacker was able to change the SSID of the router with a custom payload, they could achieve stored XSS on the device.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Asus | Zenwifi Xd4s Firmware | 3.0.0.4.386.46061 |
| Asus | Zenwifi Xt9 Firmware | 3.0.0.4.386.46061 |
| Asus | Zenwifi Xd5 Firmware | 3.0.0.4.386.46061 |
| Asus | Zenwifi Pro Et12 Firmware | 3.0.0.4.386.46061 |
| Asus | Zenwifi Pro Xt12 Firmware | 3.0.0.4.386.46061 |
| Asus | Zenwifi Ax Hybrid Firmware | 3.0.0.4.386.46061 |
| Asus | Zenwifi Et8 Firmware | 3.0.0.4.386.46061 |
| Asus | Zenwifi Xd6 Firmware | 3.0.0.4.386.46061 |
| Asus | Zenwifi Ac Mini Firmware | 3.0.0.4.386.46061 |
| Asus | Zenwifi Ax Mini Firmware | 3.0.0.4.386.46061 |
| Asus | Zenwifi Ax Firmware | 3.0.0.4.386.46061 |
| Asus | Zenwifi Ac Firmware | 3.0.0.4.386.46061 |
| Asus | Rt-Ac66u B1 Firmware | 3.0.0.4.386.46061 |
| Asus | Rt-Ax88u Firmware | 3.0.0.4.386.46061 |
| Asus | Rt-Ax82u Firmware | 3.0.0.4.386.46061 |
| Asus | Rt-Ax89x Firmware | 3.0.0.4.386.46061 |
| Asus | Rt-Ax92u Firmware | 3.0.0.4.386.46061 |
| Asus | Rt-Ax86u Firmware | 3.0.0.4.386.46061 |
| Asus | Rt-Ax68u Firmware | 3.0.0.4.386.46061 |
| Asus | Rt-Ax3000 Firmware | 3.0.0.4.386.46061 |
| Asus | Rt-Ax58u Firmware | 3.0.0.4.386.46061 |
| Asus | Rt-Ax55 Firmware | 3.0.0.4.386.46061 |
| Asus | Rt-Ax56u Firmware | 3.0.0.4.386.46061 |
| Asus | Rt-Ac66u\+ Firmware | 3.0.0.4.386.46061 |
| Asus | Rog Rapture Gt-Ac5300 Firmware | 3.0.0.4.386.46061 |
| Asus | Rog Rapture Gt-Ax11000 Firmware | 3.0.0.4.386.46061 |
| Asus | Rog Rapture Gt-Ac2900 Firmware | 3.0.0.4.386.46061 |
| Asus | Rt-Ac1300uhp Firmware | 3.0.0.4.386.46061 |
| Asus | Rt-Ac1300g\+ Firmware | 3.0.0.4.386.46061 |
| Asus | Tuf Gaming Ax5400 Firmware | 3.0.0.4.386.46061 |
| Asus | Tuf Gaming Ax3000 V2 Firmware | 3.0.0.4.386.46061 |
| Asus | Rt-Ac1200 Firmware | 3.0.0.4.386.46061 |
| Asus | Rt-Ac5300 Firmware | 3.0.0.4.386.46061 |
| Asus | Rt-Ac1200g Firmware | 3.0.0.4.386.46061 |
| Asus | Rt-Ac1200hp Firmware | 3.0.0.4.386.46061 |
| Asus | Rt-Ac1200g\+ Firmware | 3.0.0.4.386.46061 |
| Asus | Rt-Ac1200e Firmware | 3.0.0.4.386.46061 |
| Asus | Rt-Ac1200gu Firmware | 3.0.0.4.386.46061 |
| Asus | Rt-Ac3100 Firmware | 3.0.0.4.386.46061 |
| Asus | Rt-Ac58u Firmware | 3.0.0.4.386.46061 |
| Asus | Rt-Ac88u Firmware | 3.0.0.4.386.46061 |
| Asus | Rt-Ac56u Firmware | 3.0.0.4.386.46061 |
| Asus | Rt-Ac56r Firmware | 3.0.0.4.386.46061 |
| Asus | Rt-Ac56s Firmware | 3.0.0.4.386.46061 |
| Asus | Rt-Ac3200 Firmware | 3.0.0.4.386.46061 |
| Asus | Rt-Ac55u Firmware | 3.0.0.4.386.46061 |
| Asus | Rt-Ac2900 Firmware | 3.0.0.4.386.46061 |
| Asus | Rt-Ac55uhp Firmware | 3.0.0.4.386.46061 |
| Asus | Rt-Ac2600 Firmware | 3.0.0.4.386.46061 |
| Asus | Rt-Ac53 Firmware | 3.0.0.4.386.46061 |
Showing 50 of 93 affected configurations. See NVD for the full list.
References
- https://www.asus.com/uk/Networking-IoT-Servers/WiFi-Routers/ASUS-WiFi-Routers/RT-AC88U/Product, Vendor Advisory
- https://www.kroll.com/en/insights/publications/cyber/cve-2021-43702-from-discovery-to-patchExploit, Third Party Advisory
- https://www.asus.com/uk/Networking-IoT-Servers/WiFi-Routers/ASUS-WiFi-Routers/RT-AC88U/Product, Vendor Advisory
- https://www.kroll.com/en/insights/publications/cyber/cve-2021-43702-from-discovery-to-patchExploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-43702?
How severe is CVE-2021-43702?
How do I fix CVE-2021-43702?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-43696twmap v2.91_v4.33 is affected by a Cross Site Scripting (XSS…6.1
- CVE-2021-43697Workerman-ThinkPHP-Redis (last update Mar 16, 2018) is affec…6.1
- CVE-2021-43698phpWhois (last update Jun 30 2021) is affected by a Cross Si…6.1
- CVE-2021-4370The uListing plugin for WordPress is vulnerable to authoriza…9.8
- CVE-2021-43700An issue was discovered in ApiManager 1.1. there is sql inje…9.8
- CVE-2021-43701CSZ CMS 1.2.9 has a Time and Boolean-based Blind SQL Injecti…6.5
- CVE-2021-43703An Incorrect Access Control vulnerability exists in zzcms le…9.8
- CVE-2021-43707Cross Site Scripting (XSS) vulnerability exists in Maccms v1…6.1
- CVE-2021-43708The Labeling tool in Titus Classification Suite 18.8.1910.14…5.5
- CVE-2021-4371The WP Quick FrontEnd Editor plugin for WordPress is vulnera…4.3
- CVE-2021-43711The downloadFlile.cgi binary file in TOTOLINK EX200 V4.0.3c.…9.8
- CVE-2021-43712Stored XSS in Add New Employee Form in Sourcecodester Employ…5.4
Are you affected by CVE-2021-43702?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
