Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2021-32030 PoC — ASUS GT-AC2900 授权问题漏洞

Source
Associated Vulnerability
Title:ASUS GT-AC2900 授权问题漏洞 (CVE-2021-32030)
Description:ASUS GT-AC2900是中国华硕(ASUS)公司的一个路由器。 ASUS GT-AC2900 devices 3.0.0.4.386.42643之前版本存在安全漏洞,该漏洞允许管理员应用程序在处理未经认证用户的远程输入时,允许绕过认证,导致未经认证的用户访问管理员界面。
Description
ASUS GT-AC2900 devices before 3.0.0.4.386.42643 allows authentication bypass when processing remote input from an unauthenticated user, leading to unauthorized access to the administrator application. This relates to handle_request in router/httpd/httpd.c and auth_check in web_hook.o. An attacker-supplied value of '' matches the device's default value of '' in some situations.
File Snapshot

id: CVE-2021-32030 info: name: ASUS GT-AC2900 - Authentication Bypass author: gy741 severity: ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.