Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-35401


An authentication bypass vulnerability exists in the get_IFTTTTtoken.cgi functionality of Asus RT-AX82U 3.0.0.4.386_49674-ge182230. A specially-crafted HTTP request can lead to full administrative access to the device. An attacker would need to send a series of HTTP requests to exploit this vulnerability.


Published

2023-01-10T21:15:11.617

Last Modified

2024-11-21T07:11:06.070

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 8.1 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-324
  • Type: Primary
    CWE-287

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System asus rt-ax82u_firmware 3.0.0.4.386_49674-ge182230 Yes
Hardware asus rt-ax82u - No

References