Junglewise Threat Intelligence

CVE-2021-32030: ASUS Routers authentication bypass in administrator interface

CVE-2021-32030 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2025-06-02

Vendors: ASUS, D-Link.

Executive brief

ASUS Lyra Mini and GT-AC2900 routers contain a security flaw that allows unauthorized individuals to bypass login requirements and access the device's administrative interface. This could allow an attacker to take full control of the router, monitor network traffic, or change security settings. Because these devices are older and may be at the end of their service life, users are advised to update their firmware immediately or replace the hardware if updates are unavailable.

Technical details

An authentication bypass vulnerability exists in the administrator application of ASUS GT-AC2900 and Lyra Mini routers due to improper handling of remote input. The flaw is located in the handle_request function within router/httpd/httpd.c and auth_check in web_hook.o, where an attacker-supplied null character ('\0') can match the device's default value under certain conditions. This allows a remote, unauthenticated attacker to bypass authentication mechanisms and gain full administrative access via the network. CISA has confirmed this vulnerability has been exploited in the wild. Users should update to GT-AC2900 firmware 3.0.0.4.386.42643 or Lyra Mini firmware 3.0.0.4_384_46630, or disable remote WAN access as a mitigation.

Affected products

  • ASUS GT-AC2900 before 3.0.0.4.386.42643
  • ASUS Lyra Mini before 3.0.0.4_384_46630

Timeline

  • 2021-04-30: disclosed: Initial public disclosure by Atredis Partners
  • 2025-06-02: kev added: Added to CISA Known Exploited Vulnerabilities catalog

Related threats