Asus Router vulnerabilities
14 known vulnerabilities affecting asus/router.
Total CVEs
14
CISA KEV
0
Public exploits
1
Exploited in wild
2
Severity breakdown
CRITICAL3HIGH6MEDIUM5
Vulnerabilities
Page 1 of 1
CVE-2025-2492P1CRITICALCVSS 9.2ExploitedPoCv3.0.0.4_382 seriesv3.0.0.4_386 series+2 more2025-04-18
CVE-2025-2492 [CRITICAL] CWE-288 CVE-2025-2492: An improper authentication control vulnerability exists in AiCloud. This vulnerability can be trigge
An improper authentication control vulnerability exists in AiCloud. This vulnerability can be triggered by a crafted request, potentially leading to unauthorized execution of functions.
Refer to the 'ASUS Router AiCloud vulnerability' section on the ASUS Security Advisory for more information.
nvd
CVE-2024-12912P2HIGHCVSS 7.2Exploitedv3.0.0.4_382 seriesv3.0.0.4_386 series+2 more2025-01-02
CVE-2024-12912 [HIGH] CWE-20 CVE-2024-12912: An improper input insertion vulnerability in AiCloud on certain router models may lead to arbitrary
An improper input insertion vulnerability in AiCloud on certain router models may lead to arbitrary command execution.
Refer to the '01/02/2025 ASUS Router AiCloud vulnerability' section on the ASUS Security Advisory for more information.
nvd
CVE-2025-59366P2CRITICALCVSS 9.2v3.0.0.4_386v3.0.0.4_388+1 more2025-11-25
CVE-2025-59366 [CRITICAL] CWE-22 CVE-2025-59366: An authentication-bypass vulnerability exists in AiCloud. This vulnerability can be triggered by an
An authentication-bypass vulnerability exists in AiCloud. This vulnerability can be triggered by an unintended side effect of the Samba functionality, potentially leading to allow execution of specific functions without proper authorization.
Refer to the Security Update for ASUS Router Firmware section on the ASUS Security Advisory for more inform
nvd
CVE-2026-13385P2CRITICALCVSS 9.5v3.0.0.4_386 seriesv3.0.0.4_388 series+1 more2026-07-15
CVE-2026-13385 [CRITICAL] CWE-295 CVE-2026-13385: An Improper Validation of Integrity Check Value and Improper Certificate Validation in certain ASUS
An Improper Validation of Integrity Check Value and Improper Certificate Validation in certain ASUS router models allows a remote man-in-the-middle(MITM) user to make the router download and execute arbitrary command via a spoofed server.
Refer to the '
Security Update for ASUS Router Firmware ' section on the ASUS Security Advisory for more inform
nvd
CVE-2025-15101P3HIGHCVSS 8.8v3.0.0.6_1022026-03-26
CVE-2025-15101 [HIGH] CWE-78 CVE-2025-15101: An OS command injection vulnerability in the web management interface of certain ASUS router models
An OS command injection vulnerability in the web management interface of certain ASUS router models allows remote authenticated administrators to execute arbitrary system commands via a crafted parameter.
Refer to the 'Security Update for ASUS Router Firmware' section on the ASUS Security Advisory for more information.
nvd
CVE-2025-12003P3HIGHCVSS 8.2v3.0.0.4_386v3.0.0.4_388+1 more2025-11-25
CVE-2025-12003 [HIGH] CWE-22 CVE-2025-12003: A path traversal vulnerability has been identified in WebDAV, which may allow unauthenticated remote
A path traversal vulnerability has been identified in WebDAV, which may allow unauthenticated remote attackers to impact the integrity of the device.
Refer to the ' Security Update for ASUS Router Firmware' section on the ASUS Security Advisory for more information.
nvd
CVE-2025-59370P3HIGHCVSS 7.5v3.0.0.4_386v3.0.0.4_388+1 more2025-11-25
CVE-2025-59370 [HIGH] CWE-78 CVE-2025-59370: A command injection vulnerability has been identified in bwdpi. A remote, authenticated attacker cou
A command injection vulnerability has been identified in bwdpi. A remote, authenticated attacker could leverage this vulnerability to potentially execute arbitrary commands, leading to the device executing unintended instructions.
Refer to the 'Security Update for ASUS Router Firmware' section on the ASUS Security Advisory for more information.
nvd
CVE-2025-59371P3HIGHCVSS 7.5v3.0.0.4_386v3.0.0.4_388+1 more2025-11-25
CVE-2025-59371 [HIGH] CWE-330 CVE-2025-59371: An authentication bypass vulnerability has been identified in the IFTTT integration feature. A remot
An authentication bypass vulnerability has been identified in the IFTTT integration feature. A remote, authenticated attacker could leverage this vulnerability to potentially gain unauthorized access to the device. This vulnerability does not affect Wi-Fi 7 series models.
Refer to the 'Security Update for ASUS Router Firmware' section on the ASUS Secu
nvd
CVE-2024-13062P3HIGHCVSS 7.2v3.0.0.4_382 seriesv3.0.0.4_386 series+2 more2025-01-02
CVE-2024-13062 [HIGH] CWE-77 CVE-2024-13062: An unintended entry point vulnerability has been identified in certain router models, which may allo
An unintended entry point vulnerability has been identified in certain router models, which may allow for arbitrary command execution.
Refer to the ' 01/02/2025 ASUS Router AiCloud vulnerability' section on the ASUS Security Advisory for more information.
nvd
CVE-2025-59369P3MEDIUMCVSS 5.9v3.0.0.4_386v3.0.0.4_388+1 more2025-11-25
CVE-2025-59369 [MEDIUM] CWE-89 CVE-2025-59369: A SQL injection vulnerability has been identified in bwdpi. A remote, authenticated attacker could l
A SQL injection vulnerability has been identified in bwdpi. A remote, authenticated attacker could leverage this vulnerability to potentially execute arbitrary SQL queries, leading to unauthorized data access.
Refer to the 'Security Update for ASUS Router Firmware' section on the ASUS Security Advisory for more information.
nvd
CVE-2025-59372P3MEDIUMCVSS 6.9v3.0.0.4_386v3.0.0.4_388+1 more2025-11-25
CVE-2025-59372 [MEDIUM] CWE-22 CVE-2025-59372: A path traversal vulnerability has been identified in certain router models. A remote, authenticated
A path traversal vulnerability has been identified in certain router models. A remote, authenticated attacker could exploit this vulnerability to write files outside the intended directory, potentially affecting device integrity.
Refer to the 'Security Update for ASUS Router Firmware' section on the ASUS Security Advisory for more information.
nvd
CVE-2025-59365P3MEDIUMCVSS 6.9v3.0.0.4_386v3.0.0.4_388+1 more2025-11-25
CVE-2025-59365 [MEDIUM] CWE-121 CVE-2025-59365: A stack buffer overflow vulnerability has been identified in certain router models. An authenticated
A stack buffer overflow vulnerability has been identified in certain router models. An authenticated attacker may trigger this vulnerability by sending a crafted request, potentially impacting the availability of the device.
Refer to the ' Security Update for ASUS Router Firmware' section on the ASUS Security Advisory for more information.
nvd
CVE-2025-59368P3MEDIUMCVSS 6.0v3.0.0.4_386v3.0.0.4_388+1 more2025-11-25
CVE-2025-59368 [MEDIUM] CWE-191 CVE-2025-59368: An integer underflow vulnerability has been identified in Aicloud. An authenticated attacker may tri
An integer underflow vulnerability has been identified in Aicloud. An authenticated attacker may trigger this vulnerability by sending a crafted request, potentially impacting the availability of the device.
Refer to the ' Security Update for ASUS Router Firmware' section on the ASUS Security Advisory for more information.
nvd
CVE-2026-11851P3MEDIUMCVSS 5.9vASUSWRT 3.0.0.4_386 seriesvASUSWRT 3.0.0.4_388 series+1 more2026-07-15
CVE-2026-11851 [MEDIUM] CWE-89 CVE-2026-11851: Improper Neutralization of Special Elements used in an SQL Command ("SQL Injection") in the web mana
Improper Neutralization of Special Elements used in an SQL Command ("SQL Injection") in the web management interface of certain ASUS router models allows a remote authenticated user to disclose confidential information via a crafted request that bypasses existing input validation
Refer to the '
Security Update for ASUS Router Firmware ' section on th
nvd