ID

VAR-202207-0160


CVE

CVE-2021-43702


TITLE

ASUS RT-A88U Cross-Site Scripting Vulnerability

Trust: 1.2

sources: CNVD: CNVD-2022-58229 // CNNVD: CNNVD-202207-389

DESCRIPTION

ASUS RT-A88U 3.0.0.4.386_45898 is vulnerable to Cross Site Scripting (XSS). The ASUS router admin panel does not sanitize the WiFI logs correctly, if an attacker was able to change the SSID of the router with a custom payload, they could achieve stored XSS on the device. ASUS RT-A88U is a wireless router from ASUS (ASUS) in Taiwan

Trust: 1.53

sources: NVD: CVE-2021-43702 // CNVD: CNVD-2022-58229 // VULMON: CVE-2021-43702

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2022-58229

AFFECTED PRODUCTS

vendor:asusmodel:zenwifi xd4sscope:eqversion:3.0.0.4.386.46061

Trust: 1.0

vendor:asusmodel:zenwifi ac miniscope:eqversion:3.0.0.4.386.46061

Trust: 1.0

vendor:asusmodel:rt-ac58uscope:eqversion:3.0.0.4.386.46061

Trust: 1.0

vendor:asusmodel:rt-ax86uscope:eqversion:3.0.0.4.386.46061

Trust: 1.0

vendor:asusmodel:rt-ac87uscope:eqversion:3.0.0.4.386.46061

Trust: 1.0

vendor:asusmodel:rt-acrh13scope:eqversion:3.0.0.4.386.46061

Trust: 1.0

vendor:asusmodel:rt-n12vp b1scope:eqversion:3.0.0.4.386.46061

Trust: 1.0

vendor:asusmodel:rt-ac66rscope:eqversion:3.0.0.4.386.46061

Trust: 1.0

vendor:asusmodel:rt-ac2400scope:eqversion:3.0.0.4.386.46061

Trust: 1.0

vendor:asusmodel:zenwifi pro et12scope:eqversion:3.0.0.4.386.46061

Trust: 1.0

vendor:asusmodel:rt-ac5300scope:eqversion:3.0.0.4.386.46061

Trust: 1.0

vendor:asusmodel:rt-n12e c1scope:eqversion:3.0.0.4.386.46061

Trust: 1.0

vendor:asusmodel:rt-ac55uscope:eqversion:3.0.0.4.386.46061

Trust: 1.0

vendor:asusmodel:rt-ac68ufscope:eqversion:3.0.0.4.386.46061

Trust: 1.0

vendor:asusmodel:zenwifi xd6scope:eqversion:3.0.0.4.386.46061

Trust: 1.0

vendor:asusmodel:rt-ac1300g\+scope:eqversion:3.0.0.4.386.46061

Trust: 1.0

vendor:asusmodel:rt-ac2200scope:eqversion:3.0.0.4.386.46061

Trust: 1.0

vendor:asusmodel:rt-ac66u\+scope:eqversion:3.0.0.4.386.46061

Trust: 1.0

vendor:asusmodel:rt-ac56sscope:eqversion:3.0.0.4.386.46061

Trust: 1.0

vendor:asusmodel:rt-ax82uscope:eqversion:3.0.0.4.386.46061

Trust: 1.0

vendor:asusmodel:rt-ac1300uhpscope:eqversion:3.0.0.4.386.46061

Trust: 1.0

vendor:asusmodel:rt-n12hp b1scope:eqversion:3.0.0.4.386.46061

Trust: 1.0

vendor:asusmodel:rt-ac85uscope:eqversion:3.0.0.4.386.46061

Trust: 1.0

vendor:asusmodel:rt-ac1200gscope:eqversion:3.0.0.4.386.46061

Trust: 1.0

vendor:asusmodel:tuf gaming ax3000 v2scope:eqversion:3.0.0.4.386.46061

Trust: 1.0

vendor:asusmodel:rt-ac55uhpscope:eqversion:3.0.0.4.386.46061

Trust: 1.0

vendor:asusmodel:rt-ac1750 b1scope:eqversion:3.0.0.4.386.46061

Trust: 1.0

vendor:asusmodel:rt-n14uhpscope:eqversion:3.0.0.4.386.46061

Trust: 1.0

vendor:asusmodel:rt-ac68uscope:eqversion:3.0.0.4.386.46061

Trust: 1.0

vendor:asusmodel:rt-ac3100scope:eqversion:3.0.0.4.386.46061

Trust: 1.0

vendor:asusmodel:zenwifi pro xt12scope:eqversion:3.0.0.4.386.46061

Trust: 1.0

vendor:asusmodel:rt-ac51uscope:eqversion:3.0.0.4.386.46061

Trust: 1.0

vendor:asusmodel:zenwifi et8scope:eqversion:3.0.0.4.386.46061

Trust: 1.0

vendor:asusmodel:rt-ax92uscope:eqversion:3.0.0.4.386.46061

Trust: 1.0

vendor:asusmodel:rt-ac66wscope:eqversion:3.0.0.4.386.46061

Trust: 1.0

vendor:asusmodel:rt-ac66uscope:eqversion:3.0.0.4.386.46061

Trust: 1.0

vendor:asusmodel:rt-ax68uscope:eqversion:3.0.0.4.386.46061

Trust: 1.0

vendor:asusmodel:rt-ax58uscope:eqversion:3.0.0.4.386.46061

Trust: 1.0

vendor:asusmodel:rt-ax55scope:eqversion:3.0.0.4.386.46061

Trust: 1.0

vendor:asusmodel:rt-ac3200scope:eqversion:3.0.0.4.386.46061

Trust: 1.0

vendor:asusmodel:zenwifi xt9scope:eqversion:3.0.0.4.386.46061

Trust: 1.0

vendor:asusmodel:rog rapture gt-ac5300scope:eqversion:3.0.0.4.386.46061

Trust: 1.0

vendor:asusmodel:rt-ac1750scope:eqversion:3.0.0.4.386.46061

Trust: 1.0

vendor:asusmodel:rt-ac68rscope:eqversion:3.0.0.4.386.46061

Trust: 1.0

vendor:asusmodel:rt-ax3000scope:eqversion:3.0.0.4.386.46061

Trust: 1.0

vendor:asusmodel:rog rapture gt-ax11000scope:eqversion:3.0.0.4.386.46061

Trust: 1.0

vendor:asusmodel:rt-ac56uscope:eqversion:3.0.0.4.386.46061

Trust: 1.0

vendor:asusmodel:rt-ax89xscope:eqversion:3.0.0.4.386.46061

Trust: 1.0

vendor:asusmodel:zenwifi xd5scope:eqversion:3.0.0.4.386.46061

Trust: 1.0

vendor:asusmodel:zenwifi ax hybridscope:eqversion:3.0.0.4.386.46061

Trust: 1.0

vendor:asusmodel:rt-ac52u b1scope:eqversion:3.0.0.4.386.46061

Trust: 1.0

vendor:asusmodel:rt-ac1900scope:eqversion:3.0.0.4.386.46061

Trust: 1.0

vendor:asusmodel:rt-n12\+ b1scope:eqversion:3.0.0.4.386.46061

Trust: 1.0

vendor:asusmodel:rt-ac1200g\+scope:eqversion:3.0.0.4.386.46061

Trust: 1.0

vendor:asusmodel:rt-n66wscope:eqversion:3.0.0.4.386.46061

Trust: 1.0

vendor:asusmodel:zenwifi ax miniscope:eqversion:3.0.0.4.386.46061

Trust: 1.0

vendor:asusmodel:rt-ac1200escope:eqversion:3.0.0.4.386.46061

Trust: 1.0

vendor:asusmodel:rt-ac2900scope:eqversion:3.0.0.4.386.46061

Trust: 1.0

vendor:asusmodel:rt-ac53scope:eqversion:3.0.0.4.386.46061

Trust: 1.0

vendor:asusmodel:rt-ac85pscope:eqversion:3.0.0.4.386.46061

Trust: 1.0

vendor:asusmodel:rt-n19scope:eqversion:3.0.0.4.386.46061

Trust: 1.0

vendor:asusmodel:rt-ac68wscope:eqversion:3.0.0.4.386.46061

Trust: 1.0

vendor:asusmodel:rt-ac1200guscope:eqversion:3.0.0.4.386.46061

Trust: 1.0

vendor:asusmodel:rt-ax56uscope:eqversion:3.0.0.4.386.46061

Trust: 1.0

vendor:asusmodel:rt-ac51u\+scope:eqversion:3.0.0.4.386.46061

Trust: 1.0

vendor:asusmodel:rt-ax88uscope:eqversion:3.0.0.4.386.46061

Trust: 1.0

vendor:asusmodel:rt-n12d1scope:eqversion:3.0.0.4.386.46061

Trust: 1.0

vendor:asusmodel:rt-n66uscope:eqversion:3.0.0.4.386.46061

Trust: 1.0

vendor:asusmodel:rt-ac65pscope:eqversion:3.0.0.4.386.46061

Trust: 1.0

vendor:asusmodel:rt-ac1900uscope:eqversion:3.0.0.4.386.46061

Trust: 1.0

vendor:asusmodel:zenwifi axscope:eqversion:3.0.0.4.386.46061

Trust: 1.0

vendor:asusmodel:4g-ac68uscope:eqversion:3.0.0.4.386.46061

Trust: 1.0

vendor:asusmodel:zenwifi acscope:eqversion:3.0.0.4.386.46061

Trust: 1.0

vendor:asusmodel:rt-ac57uscope:eqversion:3.0.0.4.386.46061

Trust: 1.0

vendor:asusmodel:rt-n18uscope:eqversion:3.0.0.4.386.46061

Trust: 1.0

vendor:asusmodel:rt-ac68pscope:eqversion:3.0.0.4.386.46061

Trust: 1.0

vendor:asusmodel:rt-ac86uscope:eqversion:3.0.0.4.386.46061

Trust: 1.0

vendor:asusmodel:rt-ac65uscope:eqversion:3.0.0.4.386.46061

Trust: 1.0

vendor:asusmodel:rt-ac66u b1scope:eqversion:3.0.0.4.386.46061

Trust: 1.0

vendor:asusmodel:4g-ac53uscope:eqversion:3.0.0.4.386.46061

Trust: 1.0

vendor:asusmodel:rt-ac2600scope:eqversion:3.0.0.4.386.46061

Trust: 1.0

vendor:asusmodel:rt-ac87rscope:eqversion:3.0.0.4.386.46061

Trust: 1.0

vendor:asusmodel:rt-acrh17scope:eqversion:3.0.0.4.386.46061

Trust: 1.0

vendor:asusmodel:tuf gaming ax5400scope:eqversion:3.0.0.4.386.46061

Trust: 1.0

vendor:asusmodel:rt-n66rscope:eqversion:3.0.0.4.386.46061

Trust: 1.0

vendor:asusmodel:rt-n12e b1scope:eqversion:3.0.0.4.386.46061

Trust: 1.0

vendor:asusmodel:rog rapture gt-ac2900scope:eqversion:3.0.0.4.386.46061

Trust: 1.0

vendor:asusmodel:rt-ac1200hpscope:eqversion:3.0.0.4.386.46061

Trust: 1.0

vendor:asusmodel:rt-ac1900pscope:eqversion:3.0.0.4.386.46061

Trust: 1.0

vendor:asusmodel:rt-ac56rscope:eqversion:3.0.0.4.386.46061

Trust: 1.0

vendor:asusmodel:rt-ac88uscope:eqversion:3.0.0.4.386.46061

Trust: 1.0

vendor:asusmodel:rt-ac1200scope:eqversion:3.0.0.4.386.46061

Trust: 1.0

vendor:asusmodel:rt-n66c1scope:eqversion:3.0.0.4.386.46061

Trust: 1.0

vendor:asusmodel:rt-a88u 3.0.0.4.386 45898scope: - version: -

Trust: 0.6

sources: CNVD: CNVD-2022-58229 // NVD: CVE-2021-43702

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2021-43702
value: CRITICAL

Trust: 1.0

CNVD: CNVD-2022-58229
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-202207-389
value: CRITICAL

Trust: 0.6

VULMON: CVE-2021-43702
value: LOW

Trust: 0.1

nvd@nist.gov: CVE-2021-43702
severity: LOW
baseScore: 3.5
vectorString: AV:N/AC:M/AU:S/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: SINGLE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 6.8
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.1

CNVD: CNVD-2022-58229
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

nvd@nist.gov: CVE-2021-43702
baseSeverity: CRITICAL
baseScore: 9.0
vectorString: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: REQUIRED
scope: CHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 2.3
impactScore: 6.0
version: 3.1

Trust: 1.0

sources: CNVD: CNVD-2022-58229 // VULMON: CVE-2021-43702 // CNNVD: CNNVD-202207-389 // NVD: CVE-2021-43702

PROBLEMTYPE DATA

problemtype:CWE-79

Trust: 1.0

sources: NVD: CVE-2021-43702

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-202207-389

TYPE

XSS

Trust: 0.6

sources: CNNVD: CNNVD-202207-389

PATCH

title:Patch for ASUS RT-A88U Cross-Site Scripting Vulnerabilityurl:https://www.cnvd.org.cn/patchInfo/show/345646

Trust: 0.6

title:ASUS RT-A88U Fixes for cross-site scripting vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=200692

Trust: 0.6

sources: CNVD: CNVD-2022-58229 // CNNVD: CNNVD-202207-389

EXTERNAL IDS

db:NVDid:CVE-2021-43702

Trust: 2.3

db:CNVDid:CNVD-2022-58229

Trust: 0.6

db:CNNVDid:CNNVD-202207-389

Trust: 0.6

db:VULMONid:CVE-2021-43702

Trust: 0.1

sources: CNVD: CNVD-2022-58229 // VULMON: CVE-2021-43702 // CNNVD: CNNVD-202207-389 // NVD: CVE-2021-43702

REFERENCES

url:https://www.kroll.com/en/insights/publications/cyber/cve-2021-43702-from-discovery-to-patch

Trust: 2.3

url:https://www.asus.com/uk/networking-iot-servers/wifi-routers/asus-wifi-routers/rt-ac88u/

Trust: 1.7

url:https://cxsecurity.com/cveshow/cve-2021-43702/

Trust: 0.6

url:https://cwe.mitre.org/data/definitions/79.html

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

sources: CNVD: CNVD-2022-58229 // VULMON: CVE-2021-43702 // CNNVD: CNNVD-202207-389 // NVD: CVE-2021-43702

SOURCES

db:CNVDid:CNVD-2022-58229
db:VULMONid:CVE-2021-43702
db:CNNVDid:CNNVD-202207-389
db:NVDid:CVE-2021-43702

LAST UPDATE DATE

2024-08-14T15:27:14.485000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2022-58229date:2022-08-19T00:00:00
db:VULMONid:CVE-2021-43702date:2022-07-18T00:00:00
db:CNNVDid:CNNVD-202207-389date:2022-07-29T00:00:00
db:NVDid:CVE-2021-43702date:2022-07-18T15:27:57.557

SOURCES RELEASE DATE

db:CNVDid:CNVD-2022-58229date:2022-08-16T00:00:00
db:VULMONid:CVE-2021-43702date:2022-07-05T00:00:00
db:CNNVDid:CNNVD-202207-389date:2022-07-05T00:00:00
db:NVDid:CVE-2021-43702date:2022-07-05T12:15:07.830