VYPR

Router Firmware

by Asus

CVEs (7)

  • CVE-2025-15101HigMar 26, 2026
    risk 0.57cvss 8.8epss 0.01

    An OS command injection vulnerability in the web management interface of certain ASUS router models allows remote authenticated administrators to execute arbitrary system commands via a crafted parameter. Refer to the 'Security Update for ASUS Router Firmware' section on the…

  • CVE-2025-59371HigNov 25, 2025
    risk 0.49cvss epss 0.01

    An authentication bypass vulnerability has been identified in the IFTTT integration feature. A remote, authenticated attacker could leverage this vulnerability to potentially gain unauthorized access to the device. This vulnerability does not affect Wi-Fi 7 series models. Refer…

  • CVE-2025-59370HigNov 25, 2025
    risk 0.49cvss epss 0.01

    A command injection vulnerability has been identified in bwdpi. A remote, authenticated attacker could leverage this vulnerability to potentially execute arbitrary commands, leading to the device executing unintended instructions. Refer to the 'Security Update for ASUS Router…

  • CVE-2025-59372MedNov 25, 2025
    risk 0.45cvss epss 0.01

    A path traversal vulnerability has been identified in certain router models. A remote, authenticated attacker could exploit this vulnerability to write files outside the intended directory, potentially affecting device integrity. Refer to the 'Security Update for ASUS Router…

  • CVE-2025-59365MedNov 25, 2025
    risk 0.45cvss epss 0.00

    A stack buffer overflow vulnerability has been identified in certain router models. An authenticated attacker may trigger this vulnerability by sending a crafted request, potentially impacting the availability of the device. Refer to the ' Security Update for ASUS Router…

  • CVE-2026-13385CriJul 15, 2026
    risk 0.00cvss epss 0.00

    An Improper Validation of Integrity Check Value and Improper Certificate Validation in certain ASUS router models allows a remote man-in-the-middle(MITM) user to make the router download and execute arbitrary command via a spoofed server. Refer to the '  Security Update for…

  • CVE-2026-11851MedJul 15, 2026
    risk 0.00cvss epss 0.00

    Improper Neutralization of Special Elements used in an SQL Command ("SQL Injection") in the web management interface of certain ASUS router models allows a remote authenticated user to disclose confidential information via a crafted request that bypasses existing input…