CVE-2021-3128

In ASUS RT-AX3000, ZenWiFi AX (XT8), RT-AX88U, and other ASUS routers with firmware < 3.0.0.4.386.42095 or < 9.0.0.4.386.41994, when IPv6 is used, a routing loop can occur that generates excessive network traffic between an affected device and its upstream ISP's router. This occurs when a link prefix route points to a point-to-point link, a destination IPv6 address belongs to the prefix and is not a local IPv6 address, and a router advertisement is received with at least one global unique IPv6 prefix for which the on-link flag is set.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 84%
VendorProductVersion
asuszenwifi_ax_\(xt8\)_firmware
𝑥
< 3.0.0.4.386.42095
asuszenwifi_ax_\(xt8\)_firmware
𝑥
< 9.0.0.4.386.41994
asusrt-ax3000_firmware
𝑥
< 3.0.0.4.386.42095
asusrt-ax3000_firmware
𝑥
< 9.0.0.4.386.41994
asusrt-ax55_firmware
𝑥
< 3.0.0.4.386.42095
asusrt-ax55_firmware
𝑥
< 9.0.0.4.386.41994
asusrt-ax56u_firmware
𝑥
< 3.0.0.4.386.42095
asusrt-ax56u_firmware
𝑥
< 9.0.0.4.386.41994
asusrt-ax58u_firmware
𝑥
< 3.0.0.4.386.42095
asusrt-ax58u_firmware
𝑥
< 9.0.0.4.386.41994
asusrt-ax68u_firmware
𝑥
< 3.0.0.4.386.42095
asusrt-ax68u_firmware
𝑥
< 9.0.0.4.386.41994
asusrt-ax82u_firmware
𝑥
< 3.0.0.4.386.42095
asusrt-ax82u_firmware
𝑥
< 9.0.0.4.386.41994
asusrt-ax86u_firmware
𝑥
< 3.0.0.4.386.42095
asusrt-ax86u_firmware
𝑥
< 9.0.0.4.386.41994
asusrt-ax88u_firmware
𝑥
< 3.0.0.4.386.42095
asusrt-ax88u_firmware
𝑥
< 9.0.0.4.386.41994
asusrt-ac66u_b1_firmware
𝑥
< 3.0.0.4.386.42095
asusrt-ac66u_b1_firmware
𝑥
< 9.0.0.4.386.41994
asusrt-ac1750_b1_firmware
𝑥
< 3.0.0.4.386.42095
asusrt-ac1750_b1_firmware
𝑥
< 9.0.0.4.386.41994
asusrt-ac1900_firmware
𝑥
< 3.0.0.4.386.42095
asusrt-ac1900_firmware
𝑥
< 9.0.0.4.386.41994
asusrt-ac1900p_firmware
𝑥
< 3.0.0.4.386.42095
asusrt-ac1900p_firmware
𝑥
< 9.0.0.4.386.41994
asusrt-ac1900u_firmware
𝑥
< 3.0.0.4.386.42095
asusrt-ac1900u_firmware
𝑥
< 9.0.0.4.386.41994
asusrt-ac2900_firmware
𝑥
< 3.0.0.4.386.42095
asusrt-ac2900_firmware
𝑥
< 9.0.0.4.386.41994
asusrt-ac3100_firmware
𝑥
< 3.0.0.4.386.42095
asusrt-ac3100_firmware
𝑥
< 9.0.0.4.386.41994
asusrt-ac5300_firmware
𝑥
< 3.0.0.4.386.42095
asusrt-ac5300_firmware
𝑥
< 9.0.0.4.386.41994
asusrt-ac58u_firmware
𝑥
< 3.0.0.4.386.42095
asusrt-ac58u_firmware
𝑥
< 9.0.0.4.386.41994
asusrt-ac65u_firmware
𝑥
< 3.0.0.4.386.42095
asusrt-ac65u_firmware
𝑥
< 9.0.0.4.386.41994
asusrt-ac68p_firmware
𝑥
< 3.0.0.4.386.42095
asusrt-ac68p_firmware
𝑥
< 9.0.0.4.386.41994
asusrt-ac68r_firmware
𝑥
< 3.0.0.4.386.42095
asusrt-ac68r_firmware
𝑥
< 9.0.0.4.386.41994
asusrt-ac68rw_firmware
𝑥
< 3.0.0.4.386.42095
asusrt-ac68rw_firmware
𝑥
< 9.0.0.4.386.41994
asusrt-ac68u_firmware
𝑥
< 3.0.0.4.386.42095
asusrt-ac68u_firmware
𝑥
< 9.0.0.4.386.41994
asusrt-ac68w_firmware
𝑥
< 3.0.0.4.386.42095
asusrt-ac68w_firmware
𝑥
< 9.0.0.4.386.41994
asusrt-ac85u_firmware
𝑥
< 3.0.0.4.386.42095
asusrt-ac85u_firmware
𝑥
< 9.0.0.4.386.41994
asusrt-ac86u_firmware
𝑥
< 3.0.0.4.386.42095
asusrt-ac86u_firmware
𝑥
< 9.0.0.4.386.41994
asusrt-ac88u_firmware
𝑥
< 3.0.0.4.386.42095
asusrt-ac88u_firmware
𝑥
< 9.0.0.4.386.41994
𝑥
= Vulnerable software versions
References