CVE-2021-32030General(asus / gt-ac2900)

LOWCVSS 9.8 · CRITICALCISA KEV

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The administrator application on ASUS GT-AC2900 devices before 3.0.0.4.386.42643 and Lyra Mini before 3.0.0.4_384_46630 allows authentication bypass when processing remote input from an unauthenticated user, leading to unauthorized access to the administrator interface. This relates to handle_request in router/httpd/httpd.c and auth_check in web_hook.o. An attacker-supplied value of '\0' matches the device's default value of '\0' in some situations. Note: All versions of Lyra Mini and earlier which are unsupported (End-of-Life, EOL) are also affected by this vulnerability, Consumers can mitigate this vulnerability by disabling the remote access features from WAN.

0.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-06-23. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-287

Priority

LOW

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • gt-ac2900
  • gt-ac2900_firmware
  • lyra_mini
  • lyra_mini_firmware

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • General: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
gt-ac2900gt-ac2900_firmwarelyra_minilyra_mini_firmware

1 version affected across 4 products

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-06-22: 106-22
Signal classification1 categories
General
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • Loginsoft Threat Intel@Loginsoft_Intel
    General

    Cytellite recent detection targeting CVE-2021-32030 — IPTransit Business LTD Visit -- https://cti.loginsoft.com/ip/79.110.62.71 #Loginsoft #Cytellite #Cybersecurity #CVE202132030 #LOVI #ThreatIntelligence #Infosecurity #AI https://t.co/N70Z6IAuW0

    Post summary

    The tweet announces detection of activity tied to CVE‑2021‑32030, but provides no technical, exploit, or mitigation details.

    0000041
    22 followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
HWasusgt-ac2900---
OSasusgt-ac2900_firmware---
HWasuslyra_mini---
OSasuslyra_mini_firmware---

Explore more