CVE Feed

    Dashboard / CVE / CVE-2021-3128

    CVE-2021-3128

    In ASUS RT-AX3000, ZenWiFi AX (XT8), RT-AX88U, and other ASUS routers with firmware < 3.0.0.4.386.42095 or < 9.0.0.4.386.41994, when IPv6 is used, a routing loop can occur that generates excessive network traffic between an affected device and its upstream ISP's router. This occurs when a link prefix route points to a point-to-point link, a destination IPv6 address belongs to the prefix and is not a local IPv6 address, and a router advertisement is received with at least one global unique IPv6 prefix for which the on-link flag is set.

    Published:Apr 12, 2021
    Last Modified:Nov 21, 2024
    EPS:Apr 12, 2021
    EPSS Score:0.0248
    CVSS Score:7.5

    Affected Products

    Vendor
    Asus
    Product
    Rt-ac1750 B1
    Vendor
    Asus
    Product
    Rt-ac1750 B1 Firmware
    Vendor
    Asus
    Product
    Rt-ac1900
    Vendor
    Asus
    Product
    Rt-ac1900 Firmware
    Vendor
    Asus
    Product
    Rt-ac1900p
    Vendor
    Asus
    Product
    Rt-ac1900p Firmware
    Vendor
    Asus
    Product
    Rt-ac1900u
    Vendor
    Asus
    Product
    Rt-ac1900u Firmware
    Vendor
    Asus
    Product
    Rt-ac2900
    Vendor
    Asus
    Product
    Rt-ac2900 Firmware
    Vendor
    Asus
    Product
    Rt-ac3100
    Vendor
    Asus
    Product
    Rt-ac3100 Firmware
    Vendor
    Asus
    Product
    Rt-ac5300
    Vendor
    Asus
    Product
    Rt-ac5300 Firmware
    Vendor
    Asus
    Product
    Rt-ac58u
    Vendor
    Asus
    Product
    Rt-ac58u Firmware
    Vendor
    Asus
    Product
    Rt-ac65u
    Vendor
    Asus
    Product
    Rt-ac65u Firmware
    Vendor
    Asus
    Product
    Rt-ac66u B1
    Vendor
    Asus
    Product
    Rt-ac66u B1 Firmware
    Vendor
    Asus
    Product
    Rt-ac68p
    Vendor
    Asus
    Product
    Rt-ac68p Firmware
    Vendor
    Asus
    Product
    Rt-ac68r
    Vendor
    Asus
    Product
    Rt-ac68r Firmware
    Vendor
    Asus
    Product
    Rt-ac68rw
    Vendor
    Asus
    Product
    Rt-ac68rw Firmware
    Vendor
    Asus
    Product
    Rt-ac68u
    Vendor
    Asus
    Product
    Rt-ac68u Firmware
    Vendor
    Asus
    Product
    Rt-ac68w
    Vendor
    Asus
    Product
    Rt-ac68w Firmware
    Vendor
    Asus
    Product
    Rt-ac85u
    Vendor
    Asus
    Product
    Rt-ac85u Firmware
    Vendor
    Asus
    Product
    Rt-ac86u
    Vendor
    Asus
    Product
    Rt-ac86u Firmware
    Vendor
    Asus
    Product
    Rt-ac88u
    Vendor
    Asus
    Product
    Rt-ac88u Firmware
    Vendor
    Asus
    Product
    Rt-ax3000
    Vendor
    Asus
    Product
    Rt-ax3000 Firmware
    Vendor
    Asus
    Product
    Rt-ax55
    Vendor
    Asus
    Product
    Rt-ax55 Firmware
    Vendor
    Asus
    Product
    Rt-ax56u
    Vendor
    Asus
    Product
    Rt-ax56u Firmware
    Vendor
    Asus
    Product
    Rt-ax58u
    Vendor
    Asus
    Product
    Rt-ax58u Firmware
    Vendor
    Asus
    Product
    Rt-ax68u
    Vendor
    Asus
    Product
    Rt-ax68u Firmware
    Vendor
    Asus
    Product
    Rt-ax82u
    Vendor
    Asus
    Product
    Rt-ax82u Firmware
    Vendor
    Asus
    Product
    Rt-ax86u
    Vendor
    Asus
    Product
    Rt-ax86u Firmware
    Vendor
    Asus
    Product
    Rt-ax88u
    Vendor
    Asus
    Product
    Rt-ax88u Firmware
    Vendor
    Asus
    Product
    Zenwifi Ax \(xt8\)
    Vendor
    Asus
    Product
    Zenwifi Ax \(xt8\) Firmware

    Exploits

    No exploit reference

    Common Weakness Enumeration

    Common Attack Pattern Enumeration and Classification (CAPEC)

    No CAPEC recorded yet

    References

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High