CVE-2025-4569Hard-coded Credentials in Myasus

Severity
7.7HIGHNVD
EPSS
0.1%
top 75.97%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 21

Description

An insecure sensitive key storage issue was found in MyASUS. potentially allowing unauthorized actor to obtain a token that could be used to communicate with certain services. Refer to the 'Security Update for for MyASUS' section on the ASUS Security Advisory for more information.

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N

Affected Packages1 packages

CVEListV5asus/myasus4.0.35.0 and earlier

🔴Vulnerability Details

2
CVEList
CVE-2025-4569: An insecure sensitive key storage issue was found in MyASUS2025-07-21
GHSA
GHSA-w362-42cv-6j7v: An insecure sensitive key storage issue was found in MyASUS2025-07-21

📋Vendor Advisories

1
Microsoft
Kernel: information leak in nft_set_catchall_flush in net/netfilter/nf_tables_api.c2023-08-08
CVE-2025-4569 — Hard-coded Credentials in Asus Myasus | cvebase