CVE-2021-3128

    Dashboard / Vulnerabilities / CVE-2021-3128

    CVE-2021-3128

    Published: 12 Apr 2021Last Modified: 10 Mar 2026

    Summary:

    Details: In ASUS RT-AX3000, ZenWiFi AX (XT8), RT-AX88U, and other ASUS routers with firmware < 3.0.0.4.386.42095 or < 9.0.0.4.386.41994, when IPv6 is used, a routing loop can occur that generates excessive network traffic between an affected device and its upstream ISP's router. This occurs when a link prefix route points to a point-to-point link, a destination IPv6 address belongs to the prefix and is not a local IPv6 address, and a router advertisement is received with at least one global unique IPv6 prefix for which the on-link flag is set.

    References: , https://www.asus.com/Networking-IoT-Servers/Whole-Home-Mesh-WiFi-System/ZenWiFi-WiFi-Systems/ASUS-ZenWiFi-AX-XT8-/HelpDesk_BIOS/, https://www.asus.com/Networking-IoT-Servers/WiFi-6/All-series/RT-AX55/HelpDesk_BIOS/, https://www.asus.com/Networking-IoT-Servers/WiFi-6/All-series/RT-AX58U/HelpDesk_BIOS/, https://www.asus.com/Networking-IoT-Servers/WiFi-Routers/ASUS-WiFi-Routers/RT-AC66U-B1/HelpDesk_Download/, https://www.asus.com/supportonly/RT-AC1750_B1/HelpDesk_download/, https://www.asus.com/supportonly/RT-AC1900/HelpDesk_download/, https://www.asus.com/supportonly/RT-AC58U/HelpDesk_download/, https://www.asus.com/supportonly/RT-AC65U/HelpDesk_download/, https://www.asus.com/Networking-IoT-Servers/WiFi-6/All-series/RT-AX3000/HelpDesk_BIOS/, https://www.asus.com/Networking-IoT-Servers/WiFi-6/All-series/RT-AX82U/HelpDesk_BIOS/, https://www.asus.com/Networking-IoT-Servers/WiFi-6/All-series/RT-AX88U/HelpDesk_BIOS/, https://www.asus.com/supportonly/RT-AC68P/HelpDesk_download/, https://www.asus.com/supportonly/RT-AC68R/HelpDesk_download/, https://www.asus.com/supportonly/RT-AC68U/HelpDesk_download/, https://www.asus.com/supportonly/RT-AC85U/HelpDesk_download/, https://www.asus.com/supportonly/RT-AC88U/HelpDesk_download/, https://www.asus.com/Networking-IoT-Servers/WiFi-6/All-series/RT-AX68U/HelpDesk_BIOS/, https://www.asus.com/supportonly/RT-AC1900P/HelpDesk_download/, https://www.asus.com/supportonly/RT-AC2900/HelpDesk_download/, https://www.asus.com/supportonly/RT-AC5300/HelpDesk_download/, https://www.asus.com/supportonly/RT-AC68RW/HelpDesk_download/, https://www.asus.com/supportonly/RT-AC68W/HelpDesk_download/, https://www.asus.com/Networking-IoT-Servers/WiFi-6/All-series/RT-AX56U/HelpDesk_BIOS/, https://www.asus.com/Networking-IoT-Servers/WiFi-6/All-series/RT-AX86U/HelpDesk_BIOS/, https://www.asus.com/supportonly/RT-AC1900U/HelpDesk_download/, https://www.asus.com/supportonly/RT-AC3100/HelpDesk_download/, https://www.asus.com/supportonly/RT-AC86U/HelpDesk_download/

    Affected packages

    Package

    Name:

    Purl:

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    CVE-2021-3128 | CVE-DB