Skip to main content

Vendor archive

asus CVEs

Beta · best-effort

273 CVEs tagged to vendor asus49 Critical, 127 High, 94 Medium, 3 Low, 0 Unrated.

CVE-2025-15101

Published Mar 26, 2026

An OS command injection vulnerability in the web management interface of certain ASUS router models allows remote authenticated administrators to execute arbitrary system commands…

CVSS 8.6 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-12793

Published Jan 6, 2026

An uncontrolled DLL loading path vulnerability exists in AsusSoftwareManagerAgent. A local attacker may influence the application to load a DLL from an attacker-controlled locatio…

CVSS 8.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-59374

Published Dec 17, 2025

"UNSUPPORTED WHEN ASSIGNED" Certain versions of the ASUS Live Update client were distributed with unauthorized modifications introduced through a supply chain compromise. The modi…

CVSS 9.3 · Critical
evidence mentions
3
Buzz score
46.9
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2024-31161

Published Jun 14, 2024

The upload functionality of ASUS Download Master does not properly filter user input. Remote attackers with administrative privilege can exploit this vulnerability to upload any f…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2024-31160

Published Jun 14, 2024

The parameter used in the certain page of ASUS Download Master is not properly filtered for user input. A remote attacker with administrative privilege can insert JavaScript code…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-31159

Published Jun 14, 2024

The parameter used in the certain page of ASUS Download Master is not properly filtered for user input. A remote attacker with administrative privilege can insert JavaScript code…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-33220

Published May 22, 2024

An issue in the component AslO3_64.sys of ASUSTeK Computer Inc AISuite3 v3.03.36 3.03.36 allows attackers to escalate privileges and execute arbitrary code via sending crafted IOC…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-35720

Published May 3, 2024

ASUS RT-AX92U lighttpd mod_webdav.so SQL Injection Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-5716

Published Jan 19, 2024

ASUS Armoury Crate has a vulnerability in arbitrary file write and allows remote attackers to access or modify arbitrary files by sending specific HTTP requests without permission.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-47678

Published Nov 15, 2023

An improper access control vulnerability exists in RT-AC87U all versions. An attacker may read or write files that are not intended to be accessed by connecting to a target device…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-41348

Published Nov 3, 2023

ASUS RT-AX55’s authentication-related function has a vulnerability of insufficient filtering of special characters within its code-authentication module. An authenticated remote a…

CVSS 8.8 · High
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2023-41347

Published Nov 3, 2023

ASUS RT-AX55’s authentication-related function has a vulnerability of insufficient filtering of special characters within its check token module. An authenticated remote attacker…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-41346

Published Nov 3, 2023

ASUS RT-AX55’s authentication-related function has a vulnerability of insufficient filtering of special characters within its token-refresh module. An authenticated remote attacke…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-41345

Published Nov 3, 2023

ASUS RT-AX55’s authentication-related function has a vulnerability of insufficient filtering of special characters within its token-generated module. An authenticated remote attac…

CVSS 8.8 · High
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2023-41349

Published Sep 18, 2023

ASUS router RT-AX88U has a vulnerability of using externally controllable format strings within its Advanced Open VPN function. An authenticated remote attacker can exploit the ex…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-39780

Published Sep 11, 2023

On ASUS RT-AX55 3.0.0.4.386.51598 devices, authenticated attackers can perform OS command injection via the /start_apply.htm qos_bw_rulelist parameter. NOTE: for the similar "toke…

CVSS 8.8 · High
evidence mentions
6
Buzz score
57.5
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2023-39237

Published Sep 7, 2023

ASUS RT-AC86U Traffic Analyzer - Apps analysis function has insufficient filtering of special character. A remote attacker with regular user privilege can exploit this vulnerabili…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-39236

Published Sep 7, 2023

ASUS RT-AC86U Traffic Analyzer - Statistic function has insufficient filtering of special character. A remote attacker with regular user privilege can exploit this vulnerability t…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-38033

Published Sep 7, 2023

ASUS RT-AC86U unused Traffic Analyzer legacy Statistic function has insufficient filtering of special character. A remote attacker with regular user privilege can exploit this vul…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 273 CVEsPage 1 of 11