cbcvebase.
CVE-2025-2492
published 2025-04-18

CVE-2025-2492: An improper authentication control vulnerability exists in AiCloud. This vulnerability can be triggered by a crafted request, potentially leading to…

PriorityP180critical9.2CVSS 4.0
AVNACLATPPRNUINVCHVIHVALSCNSINSANEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
ITWEXPLOITVulnCheck KEVInitial access
Exploited in the wild
EPSS
1.02%
59.3th percentile
An improper authentication control vulnerability exists in AiCloud. This vulnerability can be triggered by a crafted request, potentially leading to unauthorized execution of functions. Refer to the 'ASUS Router AiCloud vulnerability' section on the ASUS Security Advisory for more information.

Affected

4 ranges
VendorProductVersion rangeFixed in
asusrouter
asusrouter
asusrouter
asusrouter

Detection & IOCsextracted from sources · hover to see the quote

ip194.233.92[.]26
ip217.15.160[.]247
urlhttp[:]//217.15.160[.]247:8088/
urlhttp[:]//217.15.160[.]247:2222/
othersubject_dn = "C=exploit, ST=exploit, L=exploit, O=exploit, OU=exploit, CN=exploit"
snort
SID 66433
snort
SID 66432
snort
SID 66430
snort
SID 66431
snort
SID 301493
yara
Unix.Backdoor.Agent-10059997-1
yara
Unix.Backdoor.Agent-10059998-0
yara
Unix.Backdoor.Agent-10059999-0
yara
Java.Backdoor.Agent-10060000-0
yara
Unix.Backdoor.Agent_mips32-10060001-0
yara
Unix.Backdoor.Agent_mips32r2-10060002-0
yara
Unix.Backdoor.Agent_armv7-10060003-0
yara
Unix.Backdoor.Agent_mips1-10060004-0
yara
Unix.Backdoor.Agent_mips32r2el-10060005-0
yara
Unix.Backdoor.Agent_mips32el-10060006-0
  • Hunt for self-signed TLS certificates on AiCloud services with a 100-year validity period — this replaced the legitimate ASUS-generated certificate in ~99% of compromised WrtHug devices and was used to fingerprint ~50,000 infected IPs.
  • Detect LONGLEASH implant traffic by matching the hardcoded User-Agent 'Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.6261.95 Safari/537.36' on non-browser processes or router-originated HTTP sessions.
  • Presence of LEASHTEST (internally named 'iot-test') ELF binary on a MIPS device is a strong indicator of compromise even though the binary itself is not directly malicious.
  • JARLEASH configuration files contain comments in Simplified Chinese; detecting JAR-based backdoors on router/embedded infrastructure with Chinese-language config comments is a high-fidelity indicator of UAT-7810 activity.
  • ·CVE-2025-2492 only affects ASUS routers with the AiCloud feature enabled; devices without AiCloud active are not exposed to this specific attack vector.
  • ·WrtHug attackers do not upgrade firmware on compromised devices, leaving them open to takeover by additional threat actors — detections should account for multi-actor compromise scenarios.
  • ·LONGLEASH supports proxying over HTTP, DNS, SOCKS, TCP, ICMP, and UDP, and can act as an intermediate C2 relay — network-layer detections must account for multi-protocol tunneling and relay hops that obscure the true C2 origin.
  • ·LONGLEASH contains a self-destruct capability that removes the implant and all traces if a suspicious connection or tampering is detected, which may hinder forensic recovery on live systems.

CVSS provenance

nvdv4.09.2CRITICALCVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vulncheck9.2CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.