cbcvebase.
CVE-2025-59366
published 2025-11-25

CVE-2025-59366: An authentication-bypass vulnerability exists in AiCloud. This vulnerability can be triggered by an unintended side effect of the Samba functionality…

PriorityP268critical9.2CVSS 4.0
AVNACLATPPRNUINVCHVIHVAHSCNSINSANEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EPSS
15.40%
96.4th percentile
An authentication-bypass vulnerability exists in AiCloud. This vulnerability can be triggered by an unintended side effect of the Samba functionality, potentially leading to allow execution of specific functions without proper authorization. Refer to the Security Update for ASUS Router Firmware section on the ASUS Security Advisory for more information.

Affected

3 ranges
VendorProductVersion rangeFixed in
asusrouter
asusrouter
asusrouter

Detection & IOCsextracted from sources · hover to see the quote

  • CVE-2025-59366 exploits chained path traversal and OS command injection flaws in ASUS routers with AiCloud enabled, allowing unauthorized function execution without user interaction
  • ·The vulnerability is triggered via an unintended side effect of the Samba functionality in AiCloud; attack surface is limited to ASUS routers with AiCloud (and implicitly Samba) enabled
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.