CVE-2021-41435: A brute-force protection bypass in CAPTCHA protection in ASUS ROG Rapture GT-AX11000, RT-AX3000, RT-AX55, R...
A brute-force protection bypass in CAPTCHA protection in ASUS ROG Rapture GT-AX11000, RT-AX3000, RT-AX55, RT-AX56U, RT-AX56U_V2, RT-AX58U, RT-AX82U, RT-AX82U GUNDAM EDITION, RT-AX86 Series(RT-AX86U/RT-AX86S), RT-AX86U ZAKU II EDITION, RT-AX88U, RT-AX92U, TUF Gaming AX3000, TUF Gaming AX5400 (TUF-AX5400), ASUS ZenWiFi XD6, ASUS ZenWiFi AX (XT8) before 3.0.0.4.386.45898, and RT-AX68U before 3.0.0.4.386.45911, allows a remote attacker to attempt any number of login attempts via sending a specific HTTP request.
Security readout for executives and security teams
Plain-English summary
Some ASUS Wi-Fi routers and ZenWiFi systems had a login protection flaw that could let a remote attacker bypass CAPTCHA-based brute-force limits and keep trying passwords. This does not itself prove account takeover, but it weakens a key control protecting router administration access.
Executive priority
Treat this as a prioritized router hygiene issue, not a confirmed emergency. Patch affected internet-edge devices promptly because successful password guessing could expose network administration, but the bundle does not document active exploitation or a direct authentication bypass.
Technical view
CVE-2021-41435 is a CAPTCHA brute-force protection bypass affecting listed ASUS GT-AX, RT-AX, TUF AX, and ZenWiFi models before specified firmware builds. The CVE says a remote attacker can send a specific HTTP request to attempt unlimited logins. No CVSS, CWE, or exploit detail is provided in the bundle.
Likely exposure
Exposure is most relevant where an affected ASUS router or mesh device has reachable administrative login surfaces, especially from untrusted networks. Devices on firmware before 3.0.0.4.386.45898 are listed as affected, except RT-AX68U before 3.0.0.4.386.45911.
Exploitation context
The source bundle says remote exploitation is possible against the login protection mechanism. It does not show public exploit availability, mass exploitation, or CISA KEV listing. KEV is false, so active exploitation should not be assumed from these sources.
Researcher notes
The record lacks CVSS, CWE, detailed affected CPEs, and exploit telemetry. Analysis should stay limited to the named models and firmware thresholds. Do not infer broader ASUS exposure without vendor confirmation. The exact HTTP behavior is intentionally not described here.
Mitigation direction
Update affected models to the fixed ASUS firmware version or later.
For RT-AX68U, update to 3.0.0.4.386.45911 or later.
For other listed models, update to 3.0.0.4.386.45898 or later.
Restrict router administration access to trusted networks only.
Use strong, unique administrator credentials.
Check ASUS model support pages for current firmware guidance.
Validation and detection
Inventory ASUS router and ZenWiFi models against the affected list.
Record each device firmware version from the administration interface.
Confirm fixed firmware is installed for the exact model.
Verify remote administration is disabled or tightly restricted.
Review authentication logs for abnormal repeated failed login attempts.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cve · low confidence lookup
CVE-2021-41435 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
0CVSS vectors
3Timeline events
1ADP providers
8Source links
Vulnerability timeline
Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.
CVE reservedCVE Program
The CVE ID was reserved by the assigning CNA.
CVE publishedCVE Program
The CVE record was published.
Nov 19, 2021, 11:26 UTC (UTC+00:00)
CVE updatedCVE Program
The CVE record metadata indicates this as the latest update time.