← Vulnerability feed

Vulnerability record · CVE-2021-41435 · published 19 November 2021

CVE-2021-41435: Asus gt-ax11000 firmware improper restriction of authentication attempts vulnerability

Asus · Gt Ax11000 Firmware

A brute-force protection bypass in CAPTCHA protection in ASUS ROG Rapture GT-AX11000, RT-AX3000, RT-AX55, RT-AX56U, RT-AX56U_V2, RT-AX58U, RT-AX82U, RT-AX82U GUNDAM EDITION, RT-AX86 Series(RT-AX86U/RT-AX86S), RT-AX86U ZAKU II EDITION, RT-AX88U, RT-AX92U, TUF Gaming AX3000, TUF Gaming AX5400 (TUF-AX5400), ASUS ZenWiFi XD6, ASUS ZenWiFi AX (XT8) before 3.0.0.4.386.45898, and RT-AX68U before 3.0.0.4.386.45911, allows a remote attacker to attempt any number of login attempts via sending a specific HTTP request.

9.8 CVSS 3.1 Critical EPSS 6.5% · top 6.5% CWE-307 · Improper restriction of authentication attempts
9.8CVSS 3.1 base score, v2 10.0
6.5%EPSS exploitation probability, 30 days
NoNot in CISA KEV
18Affected product versions listed by NVD
14References
9 Jul 2026Last modified by NVD

Description

A brute-force protection bypass in CAPTCHA protection in ASUS ROG Rapture GT-AX11000, RT-AX3000, RT-AX55, RT-AX56U, RT-AX56U_V2, RT-AX58U, RT-AX82U, RT-AX82U GUNDAM EDITION, RT-AX86 Series(RT-AX86U/RT-AX86S), RT-AX86U ZAKU II EDITION, RT-AX88U, RT-AX92U, TUF Gaming AX3000, TUF Gaming AX5400 (TUF-AX5400), ASUS ZenWiFi XD6, ASUS ZenWiFi AX (XT8) before 3.0.0.4.386.45898, and RT-AX68U before 3.0.0.4.386.45911, allows a remote attacker to attempt any number of login attempts via sending a specific HTTP request.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

18 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://rog.asus.com/networking/rog-rapture-gt-ax11000-model/helpdesk_bios ProductVendor Advisory
https://www.asus.com/Networking-IoT-Servers/Whole-Home-Mesh-WiFi-System/ZenWiFi-WiFi-Systems/ASUS-ZenWiFi-AX-XT8-/HelpDe ProductVendor Advisory
https://www.asus.com/Networking-IoT-Servers/Whole-Home-Mesh-WiFi-System/ZenWiFi-WiFi-Systems/ASUS-ZenWiFi-XD6/HelpDesk_B ProductVendor Advisory
https://www.asus.com/Networking-IoT-Servers/WiFi-Routers/ASUS-WiFi-Routers/RT-AX3000/HelpDesk_BIOS/ ProductVendor Advisory
https://www.asus.com/Networking-IoT-Servers/WiFi-Routers/ASUS-WiFi-Routers/RT-AX56U/HelpDesk_BIOS/ ProductVendor Advisory
https://www.asus.com/Networking-IoT-Servers/WiFi-Routers/ASUS-WiFi-Routers/RT-AX68U/HelpDesk_BIOS/ ProductVendor Advisory
https://www.asus.com/Networking-IoT-Servers/WiFi-Routers/All-series/RT-AX55/HelpDesk_BIOS/ ProductVendor Advisory
https://rog.asus.com/networking/rog-rapture-gt-ax11000-model/helpdesk_bios ProductVendor Advisory
https://www.asus.com/Networking-IoT-Servers/Whole-Home-Mesh-WiFi-System/ZenWiFi-WiFi-Systems/ASUS-ZenWiFi-AX-XT8-/HelpDe ProductVendor Advisory
https://www.asus.com/Networking-IoT-Servers/Whole-Home-Mesh-WiFi-System/ZenWiFi-WiFi-Systems/ASUS-ZenWiFi-XD6/HelpDesk_B ProductVendor Advisory
https://www.asus.com/Networking-IoT-Servers/WiFi-Routers/ASUS-WiFi-Routers/RT-AX3000/HelpDesk_BIOS/ ProductVendor Advisory
https://www.asus.com/Networking-IoT-Servers/WiFi-Routers/ASUS-WiFi-Routers/RT-AX56U/HelpDesk_BIOS/ ProductVendor Advisory
https://www.asus.com/Networking-IoT-Servers/WiFi-Routers/ASUS-WiFi-Routers/RT-AX68U/HelpDesk_BIOS/ ProductVendor Advisory
https://www.asus.com/Networking-IoT-Servers/WiFi-Routers/All-series/RT-AX55/HelpDesk_BIOS/ ProductVendor Advisory

Track CVE-2021-41435 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2023-39780ASUS RT-AX55 Router OS Command Injection via qos_bw_rulelistASUS RT-AX55 firmware 3.0.0.4.386.51598 fails to sanitize the qos_bw_rulelist parameter on /start_apply.htm, allowing OS command injection. An attack…KEVEPSS 40%analysed9.8CVE-2023-35087Asus rt-ac86u firmware vulnerabilityIt is identified a format string vulnerability in ASUS RT-AX56U V2 & RT-AC86U. This vulnerability is caused by lacking validation for a specific valu…EPSS 1.1%9.8CVE-2022-26376Asuswrt out-of-bounds write vulnerabilityA memory corruption vulnerability exists in the httpd unescape functionality of Asuswrt prior to 3.0.0.4.386_48706 and Asuswrt-Merlin New Gen prior t…EPSS 1.3%9.0CVE-2021-43702Asus zenwifi xd4s firmware cross-site scripting vulnerabilityASUS RT-A88U 3.0.0.4.386_45898 is vulnerable to Cross Site Scripting (XSS). The ASUS router admin panel does not sanitize the WiFI logs correctly, if…EPSS 0.98%8.8CVE-2023-41345Asus rt-ax55 firmware os command injection vulnerabilityASUS RT-AX55’s authentication-related function has a vulnerability of insufficient filtering of special characters within its token-generated module.…EPSS 1.3%8.8CVE-2023-41346Asus rt-ax55 firmware os command injection vulnerabilityASUS RT-AX55’s authentication-related function has a vulnerability of insufficient filtering of special characters within its token-refresh module. A…EPSS 1.2%8.8CVE-2023-41347Asus rt-ax55 firmware os command injection vulnerabilityASUS RT-AX55’s authentication-related function has a vulnerability of insufficient filtering of special characters within its check token module. An …EPSS 1.3%8.8CVE-2023-41348Asus rt-ax55 firmware os command injection vulnerabilityASUS RT-AX55’s authentication-related function has a vulnerability of insufficient filtering of special characters within its code-authentication mod…EPSS 1.3%

Source: NIST National Vulnerability Database (record CVE-2021-41435), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.