VYPR
Unrated severityNVD Advisory· Published Apr 12, 2021· Updated Aug 3, 2024

CVE-2021-3128

CVE-2021-3128

Description

A routing loop in ASUS routers with IPv6 enabled can cause excessive network traffic, leading to denial of service.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A routing loop in ASUS routers with IPv6 enabled can cause excessive network traffic, leading to denial of service.

Vulnerability

CVE-2021-3128 affects ASUS routers including RT-AX3000, ZenWiFi AX (XT8), RT-AX88U, and others running firmware versions prior to 3.0.0.4.386.42095 or 9.0.0.4.386.41994. When IPv6 is enabled, a routing loop occurs if a link prefix route points to a point-to-point link, a destination IPv6 address belongs to that prefix but is not a local address, and a router advertisement is received with at least one global unique IPv6 prefix for which the on-link flag is set [1][2][3][4].

Exploitation

An attacker on the same network segment or upstream can send a crafted router advertisement containing a global unique IPv6 prefix with the on-link flag set. The affected router, upon receiving such an advertisement, may create a routing loop that generates excessive traffic between the router and the upstream ISP router. No authentication is required to send the malicious advertisement, but the attacker must be able to inject IPv6 router advertisements into the network.

Impact

Successful exploitation results in a denial-of-service condition due to excessive network traffic, potentially saturating the link and causing resource exhaustion on the router. The vulnerability does not lead to information disclosure, privilege escalation, or remote code execution.

Mitigation

ASUS has addressed this vulnerability in firmware versions 3.0.0.4.386.42095 and 9.0.0.4.386.41994 (or later). Users should update their routers to the latest firmware available from the ASUS support pages [1][2][3][4]. If upgrading is not immediately possible, disabling IPv6 on the router can serve as a temporary workaround. This CVE is not listed in CISA's Known Exploited Vulnerabilities catalog.

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

4

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

27

News mentions

0

No linked articles in our index yet.