CVE Vulnerabilities

CVE-2022-35401

Use of a Key Past its Expiration Date

Published: Jan 10, 2023 | Modified: Nov 21, 2024
CVSS 3.x
8.1
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An authentication bypass vulnerability exists in the get_IFTTTTtoken.cgi functionality of Asus RT-AX82U 3.0.0.4.386_49674-ge182230. A specially-crafted HTTP request can lead to full administrative access to the device. An attacker would need to send a series of HTTP requests to exploit this vulnerability.

Weakness

The product uses a cryptographic key or password past its expiration date, which diminishes its safety significantly by increasing the timing window for cracking attacks against that key.

Affected Software

Name Vendor Start Version End Version
Rt-ax82u_firmware Asus 3.0.0.4.386_49674-ge182230 (including) 3.0.0.4.386_49674-ge182230 (including)

Potential Mitigations

References