VYPR
Vendor

Asus

Products
600
CVEs
356
Across products
531
Status
Private

Products

600
View all 600 products →

Recent CVEs

356
View all 356 CVEs →
  • CVE-2021-32030CriKEVMay 6, 2021
    risk 0.84cvss 9.8epss 0.99

    The administrator application on ASUS GT-AC2900 devices before 3.0.0.4.386.42643 and Lyra Mini before 3.0.0.4_384_46630 allows authentication bypass when processing remote input from an unauthenticated user, leading to unauthorized access to the administrator interface. This…

  • CVE-2025-59374CriKEVDec 17, 2025
    risk 0.76cvss 9.8epss 0.01

    "UNSUPPORTED WHEN ASSIGNED" Certain versions of the ASUS Live Update client were distributed with unauthorized modifications introduced through a supply chain compromise. The modified builds could cause devices meeting specific targeting conditions to perform unintended…

  • CVE-2018-5999CriJan 22, 2018
    risk 0.74cvss 9.8epss 0.87

    An issue was discovered in AsusWRT before 3.0.0.4.384_10007. In the handle_request function in router/httpd/httpd.c, processing of POST requests continues even if authentication fails.

  • CVE-2018-6000CriJan 22, 2018
    risk 0.73cvss 9.8epss 0.85

    An issue was discovered in AsusWRT before 3.0.0.4.384_10007. The do_vpnupload_post function in router/httpd/web.c in vpnupload.cgi provides functionality for setting NVRAM configuration values, which allows attackers to set the admin password and launch an SSH daemon (or enable…

  • CVE-2023-39780HigKEVSep 11, 2023
    risk 0.72cvss 8.8epss 0.34

    On ASUS RT-AX55 3.0.0.4.386.51598 devices, authenticated attackers can perform OS command injection via the /start_apply.htm qos_bw_rulelist parameter. NOTE: for the similar "token-generated module" issue, see CVE-2023-41345; for the similar "token-refresh module" issue, see…

  • CVE-2023-26602CriFeb 26, 2023
    risk 0.68cvss 9.8epss 0.17

    ASUS ASMB8 iKVM firmware through 1.14.51 allows remote attackers to execute arbitrary code by using SNMP to create extensions, as demonstrated by snmpset for NET-SNMP-EXTEND-MIB with /bin/sh for command execution.

  • CVE-2019-10709CriSep 4, 2019
    risk 0.68cvss 9.8epss 0.12

    AsusPTPFilter.sys on Asus Precision TouchPad 11.0.0.25 hardware has a Pool Overflow associated with the \\.\AsusTP device, leading to a DoS or potentially privilege escalation via a crafted DeviceIoControl call.

  • CVE-2013-4659CriMar 14, 2017
    risk 0.68cvss 9.8epss 0.14

    Buffer overflow in Broadcom ACSD allows remote attackers to execute arbitrary code via a long string to TCP port 5916. This component is used on routers of multiple vendors including ASUS RT-AC66U and TRENDnet TEW-812DRU.

  • CVE-2017-6548CriMar 9, 2017
    risk 0.68cvss 9.8epss 0.21

    Buffer overflows in networkmap on ASUS RT-N56U, RT-N66U, RT-AC66U, RT-N66R, RT-AC66R, RT-AC68U, RT-AC68R, RT-N66W, RT-AC66W, RT-AC87R, RT-AC87U, RT-AC51U, RT-AC68P, RT-N11P, RT-N12+, RT-N12E B1, RT-AC3200, RT-AC53U, RT-AC1750, RT-AC1900P, RT-N300, and RT-AC750 routers with…

  • CVE-2024-3080CriJun 14, 2024
    risk 0.67cvss 9.8epss 0.43

    Certain ASUS router models have authentication bypass vulnerability, allowing unauthenticated remote attackers to log in the device.

  • CVE-2018-14714CriMay 13, 2019
    risk 0.66cvss 9.8epss 0.27

    System command injection in appGet.cgi on ASUS RT-AC3200 version 3.0.0.4.382.50010 allows attackers to execute system commands via the "load_script" URL parameter.

  • CVE-2022-31874CriJun 17, 2022
    risk 0.65cvss 9.8epss 0.19

    ASUS RT-N53 3.0.0.4.376.3754 has a command injection vulnerability in the SystemCmd parameter of the apply.cgi interface.

  • CVE-2018-8879CriNov 21, 2019
    risk 0.65cvss 9.8epss 0.17

    Stack-based buffer overflow in Asuswrt-Merlin firmware for ASUS devices older than 384.4 and ASUS firmware before 3.0.0.4.382.50470 for devices allows remote attackers to execute arbitrary code by providing a long string to the blocking.asp page via a GET or POST request.…

  • CVE-2019-11063CriAug 29, 2019
    risk 0.65cvss 10.0epss 0.04

    A broken access control vulnerability in SmartHome app (Android versions up to 3.0.42_190515, ios versions up to 2.0.22) allows an attacker in the same local area network to list user accounts and control IoT devices that connect with its gateway (HG100) via…

  • CVE-2019-11061CriAug 29, 2019
    risk 0.65cvss 10.0epss 0.04

    A broken access control vulnerability in HG100 firmware versions up to 4.00.06 allows an attacker in the same local area network to control IoT devices that connect with itself via http://[target]/smarthome/devicecontrol without any authentication. CVSS 3.0 base score 10…

  • CVE-2025-59367CriNov 13, 2025
    risk 0.64cvss 9.8epss 0.01

    An authentication bypass vulnerability has been identified in certain DSL series routers, may allow remote attackers to gain unauthorized access into the affected system. Refer to the 'Security Update for DSL Series Router' section on the ASUS Security Advisory for more…

  • CVE-2024-42757CriAug 15, 2024
    risk 0.64cvss 9.8epss 0.01

    Command injection vulnerability in Asus RT-N15U 3.0.0.4.376_3754 allows a remote attacker to execute arbitrary code via the netstat function page.

  • CVE-2024-33278CriJun 24, 2024
    risk 0.64cvss 9.8epss 0.01

    Buffer Overflow vulnerability in ASUS router RT-AX88U with firmware versions v3.0.0.4.388_24198 allows a remote attacker to execute arbitrary code via the connection_state_machine due to improper length validation for the cookie field.

  • CVE-2024-3912CriJun 14, 2024
    risk 0.64cvss 9.8epss 0.01

    Certain models of ASUS routers have an arbitrary firmware upload vulnerability. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary system commands on the device.

  • CVE-2024-30804CriApr 26, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue discovered in the DeviceIoControl component in ASUS Fan_Xpert before v.10013 allows an attacker to execute arbitrary code via crafted IOCTL requests.