CVE-2025-59366
published 2025-11-25CVE-2025-59366: An authentication-bypass vulnerability exists in AiCloud. This vulnerability can be triggered by an unintended side effect of the Samba functionality…
PriorityP268critical9.2CVSS 4.0
AVNACLATPPRNUINVCHVIHVAHSCNSINSANEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EPSS
15.40%
96.4th percentile
An authentication-bypass vulnerability exists in AiCloud. This vulnerability can be triggered by an unintended side effect of the Samba functionality, potentially leading to allow execution of specific functions without proper authorization.
Refer to the Security Update for ASUS Router Firmware section on the ASUS Security Advisory for more information.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| asus | router | — | — |
| asus | router | — | — |
| asus | router | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2025-59366 exploits chained path traversal and OS command injection flaws in ASUS routers with AiCloud enabled, allowing unauthorized function execution without user interaction ↗
- ·The vulnerability is triggered via an unintended side effect of the Samba functionality in AiCloud; attack surface is limited to ASUS routers with AiCloud (and implicitly Samba) enabled ↗
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Checkpoint
1st December – Threat Intelligence Report
blogs_checkpoint·2025-12-01
CVE-2024-10914 1st December – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 1st December – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 1st December, please download our Threat Intelligence Bulletin .
TOP ATTACKS AND BREACHES
OpenAI has experienced a data breach resulting from a compromise at third-party analytics provider Mixpanel, which exposed limited information of some ChatGPT API clients. The leaked data includes names, email addresses, approximate location, operating system, browser information, referring websites, and organization or u
Bleepingcomputer
ASUS warns of new critical auth bypass flaw in AiCloud routers
blogs_bleepingcomputer·2025-11-26·CVSS 8.2
CVE-2025-59366 [HIGH] ASUS warns of new critical auth bypass flaw in AiCloud routers
## ASUS warns of new critical auth bypass flaw in AiCloud routers
## Sergiu Gatlan
ASUS has released new firmware to patch nine security vulnerabilities, including a critical authentication bypass flaw in routers with AiCloud enabled.
AiCloud is a cloud-based remote access feature that comes with many ASUS routers, turning them into private cloud servers for remote media streaming and cloud storage.
As the Taiwanese electronics manufacturer explained, the CVE-2025-59366 vulnerability "can be triggered by an unintended side effect of the Samba functionality, potentially leading to allow execution of specific functions without proper authorization."
Remote attackers without privileges can exploit it by chaining a path traversal and an OS command injection weakness in low-complexity atta
2025-11-25
Published