VYPR
Unrated severityNVD Advisory· Published Feb 5, 2021· Updated Aug 3, 2024

CVE-2021-3229

CVE-2021-3229

Description

Denial-of-service vulnerability in ASUSWRT on RT-AX3000 allows attacker to disrupt device setup services via continuous login errors.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Denial-of-service vulnerability in ASUSWRT on RT-AX3000 allows attacker to disrupt device setup services via continuous login errors.

Vulnerability

A denial-of-service vulnerability exists in ASUSWRT firmware versions 3.0.0.4.384_10177 and earlier on ASUS RT-AX3000 routers [1]. The vulnerability allows an attacker to disrupt device setup services by repeatedly sending login attempts that fail.

Exploitation

An unauthenticated attacker can exploit this vulnerability by sending a continuous stream of login requests with incorrect credentials to the router's web interface. The repeated login errors cause the setup service to become unresponsive.

Impact

Successful exploitation leads to denial-of-service (DoS) of the device setup services, preventing legitimate users from accessing and configuring the router until the attack ceases or the router is rebooted.

Mitigation

As of the publication date (2021-02-05), no official patch or workaround has been disclosed in the available references. Users are advised to check for firmware updates from ASUS and consider limiting exposure by restricting access to the router's management interface to trusted networks.

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • ASUSWRT ASUS/RT-AX3000 firmwaredescription
  • Asus/RT-AX3000llm-fuzzy
    Range: <=3.0.0.4.384_10177

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

2

News mentions

0

No linked articles in our index yet.