CVE-2021-43702

CRITICALCVSS 9/10EPSS 0.83%

Last modified

CVE-2021-43702 is a critical-severity vulnerability rated 9/10 on the CVSS scale. ASUS RT-A88U 3.0.0.4.386_45898 is vulnerable to Cross Site Scripting (XSS). The ASUS router admin panel does not sanitize the WiFI logs correctly, if an attacker was able to change the SSID of the router with a custom payload, they could achieve stored XSS on the device.. EPSS estimates a 0.83% chance of exploitation in the next 30 days.

Description

ASUS RT-A88U 3.0.0.4.386_45898 is vulnerable to Cross Site Scripting (XSS). The ASUS router admin panel does not sanitize the WiFI logs correctly, if an attacker was able to change the SSID of the router with a custom payload, they could achieve stored XSS on the device.

Metrics

CVSS 3.1
9/10

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H

EPSS Probability
0.83%

53.0th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
AsusZenwifi Xd4s Firmware3.0.0.4.386.46061
AsusZenwifi Xt9 Firmware3.0.0.4.386.46061
AsusZenwifi Xd5 Firmware3.0.0.4.386.46061
AsusZenwifi Pro Et12 Firmware3.0.0.4.386.46061
AsusZenwifi Pro Xt12 Firmware3.0.0.4.386.46061
AsusZenwifi Ax Hybrid Firmware3.0.0.4.386.46061
AsusZenwifi Et8 Firmware3.0.0.4.386.46061
AsusZenwifi Xd6 Firmware3.0.0.4.386.46061
AsusZenwifi Ac Mini Firmware3.0.0.4.386.46061
AsusZenwifi Ax Mini Firmware3.0.0.4.386.46061
AsusZenwifi Ax Firmware3.0.0.4.386.46061
AsusZenwifi Ac Firmware3.0.0.4.386.46061
AsusRt-Ac66u B1 Firmware3.0.0.4.386.46061
AsusRt-Ax88u Firmware3.0.0.4.386.46061
AsusRt-Ax82u Firmware3.0.0.4.386.46061
AsusRt-Ax89x Firmware3.0.0.4.386.46061
AsusRt-Ax92u Firmware3.0.0.4.386.46061
AsusRt-Ax86u Firmware3.0.0.4.386.46061
AsusRt-Ax68u Firmware3.0.0.4.386.46061
AsusRt-Ax3000 Firmware3.0.0.4.386.46061
AsusRt-Ax58u Firmware3.0.0.4.386.46061
AsusRt-Ax55 Firmware3.0.0.4.386.46061
AsusRt-Ax56u Firmware3.0.0.4.386.46061
AsusRt-Ac66u\+ Firmware3.0.0.4.386.46061
AsusRog Rapture Gt-Ac5300 Firmware3.0.0.4.386.46061
AsusRog Rapture Gt-Ax11000 Firmware3.0.0.4.386.46061
AsusRog Rapture Gt-Ac2900 Firmware3.0.0.4.386.46061
AsusRt-Ac1300uhp Firmware3.0.0.4.386.46061
AsusRt-Ac1300g\+ Firmware3.0.0.4.386.46061
AsusTuf Gaming Ax5400 Firmware3.0.0.4.386.46061
AsusTuf Gaming Ax3000 V2 Firmware3.0.0.4.386.46061
AsusRt-Ac1200 Firmware3.0.0.4.386.46061
AsusRt-Ac5300 Firmware3.0.0.4.386.46061
AsusRt-Ac1200g Firmware3.0.0.4.386.46061
AsusRt-Ac1200hp Firmware3.0.0.4.386.46061
AsusRt-Ac1200g\+ Firmware3.0.0.4.386.46061
AsusRt-Ac1200e Firmware3.0.0.4.386.46061
AsusRt-Ac1200gu Firmware3.0.0.4.386.46061
AsusRt-Ac3100 Firmware3.0.0.4.386.46061
AsusRt-Ac58u Firmware3.0.0.4.386.46061
AsusRt-Ac88u Firmware3.0.0.4.386.46061
AsusRt-Ac56u Firmware3.0.0.4.386.46061
AsusRt-Ac56r Firmware3.0.0.4.386.46061
AsusRt-Ac56s Firmware3.0.0.4.386.46061
AsusRt-Ac3200 Firmware3.0.0.4.386.46061
AsusRt-Ac55u Firmware3.0.0.4.386.46061
AsusRt-Ac2900 Firmware3.0.0.4.386.46061
AsusRt-Ac55uhp Firmware3.0.0.4.386.46061
AsusRt-Ac2600 Firmware3.0.0.4.386.46061
AsusRt-Ac53 Firmware3.0.0.4.386.46061

Showing 50 of 93 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2021-43702?
ASUS RT-A88U 3.0.0.4.386_45898 is vulnerable to Cross Site Scripting (XSS). The ASUS router admin panel does not sanitize the WiFI logs correctly, if an attacker was able to change the SSID of the router with a custom payload, they could achieve stored XSS on the device.
How severe is CVE-2021-43702?
CVE-2021-43702 has a CVSS score of 9/10 (CRITICAL severity). The EPSS model estimates a 0.83% probability of exploitation in the next 30 days.
How do I fix CVE-2021-43702?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2021-43702?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST