Critical severityNVD Advisory· Published Apr 18, 2025· Updated Jun 17, 2026
CVE-2025-2492
CVE-2025-2492
Description
An improper authentication control vulnerability exists in AiCloud. This vulnerability can be triggered by a crafted request, potentially leading to unauthorized execution of functions.
Refer to the 'ASUS Router AiCloud vulnerability' section on the ASUS Security Advisory for more information.
Affected products
1Patches
Vulnerability mechanics
References
1News mentions
3- China-Linked UAT-7810 Expands ORB Network With New LONGLEASH MalwareThe Hacker News · Jul 8, 2026
- Chinese hackers develop LONGLEASH malware to expand ORB networkBleepingComputer · Jul 7, 2026
- UAT-7810 continues building ORB networks using new malwareCisco Talos Intelligence · Jul 7, 2026