Use of a Key Past its Expiration Date in Asus products - CVE-2022-35401

 

Use of a Key Past its Expiration Date in Asus products - CVE-2022-35401

Published: January 17, 2023 / Updated: June 20, 2023


Vulnerability identifier: #VU71218
CSH Severity: High
CVSS v4: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-35401
CWE-ID: CWE-324
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to authentication bypass issue in the get_IFTTTTtoken.cgi functionality. A remote attacker can send specially crafted HTTP requests and gain full administrative access to the device.


Affected software

RT-AX82U
GS-AX3000
GT-AXE16000
GS-AX5400
GT6
TUF-AX5400
RT-AX86S
RT-AX86U
RT-AX86U PRO
ZenWiFi XT8_V2
ZenWiFi XT8
ZenWiFi XT9
GT-AX11000
GT-AX6000
GT-AXE11000 PRO
RT-AX58U
RT-AX3000
GT-AXE11000
TUF-AX6000

How to mitigate CVE-2022-35401

Install updates from vendor's website.

RT-AX82U - update to 3.0.0.4.388.23285
GS-AX3000 - update to 1.4.8.3
GT-AXE16000 - update to 3.0.0.4.388.23012
GS-AX5400 - update to 3.0.0.4.388.23012
GT6 - update to 3.0.0.4.388.23145
TUF-AX5400 - update to 3.0.0.4.388.23285
RT-AX86S - update to 3.0.0.4.388.23285
RT-AX86U - update to 3.0.0.4.388.23285
RT-AX86U PRO - update to 3.0.0.4.388.23285
ZenWiFi XT8_V2 - update to 3.0.0.4.388.23285
ZenWiFi XT8 - update to 3.0.0.4.388.23285
ZenWiFi XT9 - update to 3.0.0.4.388.23285
GT-AX11000 - update to 3.0.0.4.388.23285
GT-AX6000 - update to 3.0.0.4.388.23285
GT-AXE11000 PRO - update to 3.0.0.4.388.23285
RT-AX58U - update to 3.0.0.4.388.23403
RT-AX3000 - update to 3.0.0.4.388.23403
GT-AXE11000 - update to 3.0.0.4.388.23482
TUF-AX6000 - update to 3.0.0.4.388.31927

External References

Related Security Bulletins