S4E just found a low-severity finding from [ai] web application external link detection scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-32030 Scanner

Targets the handle_request function in httpd.c and auth_check in web_hook.o, allowing an attacker to bypass authentication by supplying a null byte value.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2021-32030
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

The administrator application on ASUS GT-AC2900 devices before 3.0.0.4.386.42643 and Lyra Mini before 3.0.0.4_384_46630 allows authentication bypass when processing remote input from an unauthenticated user, leading to unauthorized access to the administrator interface. This relates to handle_request in router/httpd/httpd.c and auth_check in web_hook.o. An attacker-supplied value of '\0' matches the device's default value of '\0' in some situations. Note: All versions of Lyra Mini and earlier which are unsupported (End-of-Life, EOL) are also affected by this vulnerability, Consumers can mitigate this vulnerability by disabling the remote access features from WAN.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

The ASUS GT-AC2900 is a high-performance dual-band wireless router designed for homes and small offices, offering fast and reliable internet connectivity. Its administrator application is a web-based interface used to manage and configure router settings, accessible from any device on the network. This application is critical for maintaining network security and functionality.

CVE-2021-32030 is a critical authentication bypass vulnerability in the ASUS GT-AC2900 administrator application. It arises due to improper handling of authentication checks in the device's firmware, specifically in the handle_request function within router/httpd/httpd.c and the auth_check function in web_hook.o. The flaw allows an attacker to bypass authentication by providing a null byte value that matches the default value in certain conditions.

The vulnerability is triggered when an attacker sends a specially crafted HTTP request to the router's web interface. The vulnerable endpoint is the administrator login page, where the auth_check function fails to properly validate the authentication token when a null byte is supplied. This bypasses the standard authentication mechanism, granting unauthorized access to the admin panel.

If exploited, an attacker gains full administrative control over the router, enabling them to modify network settings, intercept traffic, deploy malware, or launch further attacks on the internal network. With a CVSS score of 9.8, this vulnerability poses a severe risk to network security and data integrity.

Solution Advice
  • Update the ASUS GT-AC2900 firmware to the latest version that patches CVE-2021-32030.
  • Change the default administrator username and password to strong, unique credentials.
  • Disable remote management access to the router's web interface from the internet.
  • Enable HTTPS for the administrator interface to encrypt traffic and prevent interception.
  • Implement network segmentation to isolate the router from critical systems.
  • Regularly monitor router logs for unauthorized access attempts.
  • Use a firewall to restrict access to the router's management interface to trusted IP addresses only.
  • Consider using a VPN for remote administration instead of exposing the web interface.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

ASUS GT-AC2900 Auth Bypass Scanner | S4E Free Check