SB2025022120 - Improper Authentication in ASUS GT-AC2900 and Lyra Mini
Published: February 21, 2025 Updated: June 2, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper Authentication (CVE-ID: CVE-2021-32030)
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to an error when processing authentication requests. A remote attacker can bypass authentication process and gain unauthorized access to the application.
Remediation
Install update from vendor's website.
References
- https://github.com/atredispartners/advisories/blob/master/ATREDIS-2020-0010.md
- https://www.asus.com/Networking-IoT-Servers/WiFi-Routers/ASUS-Gaming-Routers/RT-AC2900/HelpDesk_BIOS/
- https://www.asus.com/us/supportonly/lyra%20mini/helpdesk_bios/
- https://www.atredis.com/blog/2021/4/30/asus-authentication-bypass
- https://jvn.jp/en/vu/JVNVU97639704/index.html