VYPR

Vendor CVEs

Asus

All CVEs

369 total · sorted by risk
  • CVE-2026-19397HigSep 8, 2026
    risk 0.50cvss —epss 0.00

    Missing authentication for a critical function in ASUS Control Center Express Agent allows an unauthenticated nearby user to control the host via a direct connection to the agent when the host has an active login session. Refer to the '  Security Update for ASUS Control Center…

  • CVE-2025-4569HigJul 21, 2025
    risk 0.50cvss —epss 0.00

    An insecure sensitive key storage issue was found in MyASUS. potentially allowing unauthorized actor to obtain a token that could be used to communicate with certain services. Refer to the 'Security Update for for MyASUS' section on the ASUS Security Advisory for more…

  • CVE-2023-35086HigJul 21, 2023
    risk 0.50cvss 7.2epss 0.39

    It is identified a format string vulnerability in ASUS RT-AX56U V2 & RT-AC86U. This vulnerability is caused by directly using input as a format string when calling syslog in logmessage_normal function, in the do_detwan_cgi module of httpd. A remote attacker with administrator…

  • CVE-2022-38393HigJan 10, 2023
    risk 0.50cvss 7.5epss 0.19

    A denial of service vulnerability exists in the cfg_server cm_processConnDiagPktList opcode of Asus RT-AX82U 3.0.0.4.386_49674-ge182230 router's configuration service. A specially-crafted network packet can lead to denial of service. An attacker can send a malicious packet to…

  • CVE-2022-22262HigMar 1, 2022
    risk 0.50cvss 7.7epss 0.00

    ROG Live Service’s function for deleting temp files created by installation has an improper link resolution before file access vulnerability. Since this function does not validate the path before deletion, an unauthenticated local attacker can create an unexpected symbolic…

  • CVE-2020-12695HigJun 8, 2020
    risk 0.50cvss 7.5epss 0.15

    The Open Connectivity Foundation UPnP specification before 2020-04-17 does not forbid the acceptance of a subscription request with a delivery URL on a different network segment than the fully qualified event-subscription URL, aka the CallStranger issue.

  • CVE-2025-59371HigNov 25, 2025
    risk 0.49cvss —epss 0.01

    An authentication bypass vulnerability has been identified in the IFTTT integration feature. A remote, authenticated attacker could leverage this vulnerability to potentially gain unauthorized access to the device. This vulnerability does not affect Wi-Fi 7 series models. Refer…

  • CVE-2025-59370HigNov 25, 2025
    risk 0.49cvss —epss 0.01

    A command injection vulnerability has been identified in bwdpi. A remote, authenticated attacker could leverage this vulnerability to potentially execute arbitrary commands, leading to the device executing unintended instructions. Refer to the 'Security Update for ASUS Router…

  • CVE-2024-26342HigFeb 28, 2024
    risk 0.49cvss 7.5epss 0.01

    A Null pointer dereference in usr/sbin/httpd in ASUS AC68U 3.0.0.4.384.82230 allows remote attackers to trigger DoS via network packet.

  • CVE-2023-39086HigAug 8, 2023
    risk 0.49cvss 7.5epss 0.00

    ASUS RT-AC66U B1 3.0.0.4.286_51665 was discovered to transmit sensitive information in cleartext.

  • CVE-2023-34359HigJul 31, 2023
    risk 0.49cvss 7.5epss 0.01

    ASUS RT-AX88U's httpd is subject to an unauthenticated DoS condition. A remote attacker can send a specially crafted request to the device which causes the httpd binary to crash within the "do_json_decode()" function of ej.c, resulting in a DoS condition.

  • CVE-2023-34358HigJul 31, 2023
    risk 0.49cvss 7.5epss 0.01

    ASUS RT-AX88U's httpd is subject to an unauthenticated DoS condition. A remote attacker can send a specially crafted request to a device which contains a specific user agent, causing the httpd binary to crash during a string comparison performed within web.c, resulting in a DoS…

  • CVE-2023-34942HigJun 12, 2023
    risk 0.49cvss 7.5epss 0.01

    Asus RT-N10LX Router v2.0.0.39 was discovered to contain a stack overflow via the mac parameter at /start-apply.html. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

  • CVE-2023-34940HigJun 12, 2023
    risk 0.49cvss 7.5epss 0.01

    Asus RT-N10LX Router v2.0.0.39 was discovered to contain a stack overflow via the url parameter at /start-apply.html. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

  • CVE-2021-37316HigFeb 3, 2023
    risk 0.49cvss 7.5epss 0.01

    SQL injection vulnerability in Cloud Disk in ASUS RT-AC68U router firmware version before 3.0.0.4.386.41634 allows remote attackers to view sensitive information via /etc/shadow.

  • CVE-2022-38105HigJan 10, 2023
    risk 0.49cvss 7.5epss 0.01

    An information disclosure vulnerability exists in the cm_processREQ_NC opcode of Asus RT-AX82U 3.0.0.4.386_49674-ge182230 router's configuration service. A specially-crafted network packets can lead to a disclosure of sensitive information. An attacker can send a network request…

  • CVE-2020-23648HigOct 19, 2022
    risk 0.49cvss 7.5epss 0.01

    Asus RT-N12E 2.0.0.39 is affected by an incorrect access control vulnerability. Through system.asp / start_apply.htm, an attacker can change the administrator password without any authentication.

  • CVE-2021-3254HigMay 11, 2022
    risk 0.49cvss 7.5epss 0.02

    Asus DSL-N14U-B1 1.1.2.3_805 allows remote attackers to cause a Denial of Service (DoS) via a TCP SYN scan using nmap.

  • CVE-2021-45757HigMar 23, 2022
    risk 0.49cvss 7.5epss 0.01

    ASUS AC68U <=3.0.0.4.385.20852 is affected by a buffer overflow in blocking.cgi, which may cause a denial of service (DoS).

  • CVE-2021-46247HigFeb 17, 2022
    risk 0.49cvss 7.5epss 0.01

    The use of a hard-coded cryptographic key significantly increases the possibility encrypted data may be recovered from ASUS CMAX6000 v1.02.00.

  • CVE-2021-41436HigNov 19, 2021
    risk 0.49cvss 7.5epss 0.05

    An HTTP request smuggling in web application in ASUS ROG Rapture GT-AX11000, RT-AX3000, RT-AX55, RT-AX56U, RT-AX56U_V2, RT-AX58U, RT-AX82U, RT-AX82U GUNDAM EDITION, RT-AX86 Series(RT-AX86U/RT-AX86S), RT-AX86U ZAKU II EDITION, RT-AX88U, RT-AX92U, TUF Gaming AX3000, TUF Gaming…

  • CVE-2021-3128HigApr 12, 2021
    risk 0.49cvss 7.5epss 0.02

    In ASUS RT-AX3000, ZenWiFi AX (XT8), RT-AX88U, and other ASUS routers with firmware < 3.0.0.4.386.42095 or < 9.0.0.4.386.41994, when IPv6 is used, a routing loop can occur that generates excessive network traffic between an affected device and its upstream ISP's router. This…

  • CVE-2021-3229HigFeb 5, 2021
    risk 0.49cvss 7.5epss 0.03

    Denial of service in ASUSWRT ASUS RT-AX3000 firmware versions 3.0.0.4.384_10177 and earlier versions allows an attacker to disrupt the use of device setup services via continuous login error.

  • CVE-2021-3166HigJan 18, 2021
    risk 0.49cvss 7.5epss 0.03

    An issue was discovered on ASUS DSL-N14U-B1 1.1.2.3_805 devices. An attacker can upload arbitrary file content as a firmware update when the filename Settings_DSL-N14U-B1.trx is used. Once this file is loaded, shutdown measures on a wide range of services are triggered as if it…

  • CVE-2020-29656HigDec 9, 2020
    risk 0.49cvss 7.5epss 0.01

    An information disclosure vulnerability exists in RT-AC88U Download Master before 3.1.0.108. A direct access to /downloadmaster/dm_apply.cgi?action_mode=initial&download_type=General&special_cgi=get_language makes it possible to reach "unknown functionality" in a "known to be…

  • CVE-2020-29655HigDec 9, 2020
    risk 0.49cvss 7.5epss 0.01

    An injection vulnerability exists in RT-AC88U Download Master before 3.1.0.108. Accessing Main_Login.asp?flag=1&productname=FOOBAR&url=/downloadmaster/task.asp will redirect to the login site, which will show the value of the parameter productname within the title. An attacker…

  • CVE-2018-20335HigMar 20, 2020
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in ASUSWRT 3.0.0.4.384.20308. An unauthenticated user can trigger a DoS of the httpd service via the /APP_Installation.asp?= URI.

  • CVE-2018-20333HigMar 20, 2020
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in ASUSWRT 3.0.0.4.384.20308. An unauthenticated user can request /update_applist.asp to see if a USB device is attached to the router and if there are apps installed on the router.

  • CVE-2019-15912HigDec 20, 2019
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered on ASUS HG100, MW100, WS-101, TS-101, AS-101, MS-101, DL-101 devices using ZigBee PRO. Attackers can use the ZigBee trust center rejoin procedure to perform mutiple denial of service attacks.

  • CVE-2019-15910HigDec 20, 2019
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered on ASUS HG100, MW100, WS-101, TS-101, AS-101, MS-101, DL-101 devices using ZigBee PRO. Attackers can utilize the "discover ZigBee network procedure" to perform a denial of service attack.

  • CVE-2018-20336HigSep 17, 2019
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in ASUSWRT 3.0.0.4.384.20308. There is a stack-based buffer overflow issue in parse_req_queries function in wanduck.c via a long string over UDP, which may lead to an information leak.

  • CVE-2019-11060HigAug 29, 2019
    risk 0.49cvss 7.5epss 0.03

    The web api server on Port 8080 of ASUS HG100 firmware up to 1.05.12, which is vulnerable to Slowloris HTTP Denial of Service: an attacker can cause a Denial of Service (DoS) by sending headers very slowly to keep HTTP or HTTPS connections and associated resources alive for a…

  • CVE-2018-17127HigSep 17, 2018
    risk 0.49cvss 7.5epss 0.01

    blocking_request.cgi on ASUS GT-AC5300 devices through 3.0.0.4.384_32738 allows remote attackers to cause a denial of service (NULL pointer dereference and device crash) via a request that lacks a timestap parameter.

  • CVE-2018-17020HigSep 13, 2018
    risk 0.49cvss 7.5epss 0.02

    ASUS GT-AC5300 devices with firmware through 3.0.0.4.384_32738 allow remote attackers to cause a denial of service via a single "GET / HTTP/1.1\r\n" line.

  • CVE-2017-5892HigMay 10, 2017
    risk 0.49cvss 7.5epss 0.01

    ASUS RT-AC* and RT-N* devices with firmware before 3.0.0.4.380.7378 allow JSONP Information Disclosure such as a network map.

  • CVE-2022-26668HigJun 20, 2022
    risk 0.48cvss 7.3epss 0.01

    ASUS Control Center API has a broken access control vulnerability. An unauthenticated remote attacker can call privileged API functions to perform partial system operations or cause partial disrupt of service.

  • CVE-2022-26672HigApr 22, 2022
    risk 0.48cvss 7.3epss 0.01

    ASUS WebStorage has a hardcoded API Token in the APP source code. An unauthenticated remote attacker can use this token to establish connections with the server and carry out login attempts to general user accounts. A successful login to a general user account allows the…

  • CVE-2015-7788HigDec 30, 2015
    risk 0.48cvss 7.3epss 0.02

    ASUS Japan WL-330NUL devices with firmware before 3.0.0.42 allow remote attackers to execute arbitrary commands via unspecified vectors.

  • CVE-2019-25764HigJul 17, 2026
    risk 0.47cvss —epss 0.00

    **UNSUPPORTED WHEN ASSIGNED**  Exposed IOCTL with Insufficient Access Control in the ASUS AURA SYNC driver allows a local user to bypass the driver's verification and invoke arbitrary IOCTLs, resulting in privilege escalation. Refer to the 'End-of-Life Notice and Driver Update…

  • CVE-2026-8919HigJul 15, 2026
    risk 0.47cvss —epss 0.00

    Permissive Cross-domain Security Policy with Untrusted Domains in ASUS GameSDK allows a remote user to obtain a local user’s NTLM hash by convincing the user to visit a crafted web page that sends a request containing a UNC path to the application’s local service endpoint.…

  • CVE-2026-8070HigMay 29, 2026
    risk 0.47cvss —epss 0.00

    Incorrect permission assignment for a critical resource in Armoury Crate allows a local user to bypass the driver’s validation mechanism, resulting in unauthorized read and write access to physical memory.Refer to the '  Security Update for Armoury Crate App   ' section on…

  • CVE-2026-7480HigMay 29, 2026
    risk 0.47cvss —epss 0.00

    An Incorrect Permission Assignment for Critical Resource vulnerability in ASUS System Control Interface allows a local user to elevate privileges to SYSTEM and execute arbitrary code via a crafted RPC call that bypass the validation mechanism. Refer to the 'Security Update for…

  • CVE-2025-9338HigNov 6, 2025
    risk 0.47cvss —epss 0.00

    A improper restriction of operations within the bounds of a memory buffer exists in AsIO3.sys driver. This vulnerability can be triggered by manually executing a specially crafted process, potentially leading to local privilage escalation. For additional information, please…

  • CVE-2024-13062HigJan 2, 2025
    risk 0.47cvss 7.2epss 0.01

    An unintended entry point vulnerability has been identified in certain router models, which may allow for arbitrary command execution. Refer to the ' 01/02/2025 ASUS Router AiCloud vulnerability' section on the ASUS Security Advisory for more information.

  • CVE-2024-12912HigJan 2, 2025
    risk 0.47cvss 7.2epss 0.01

    An improper input insertion vulnerability in AiCloud on certain router models may lead to arbitrary command execution. Refer to the '01/02/2025 ASUS Router AiCloud vulnerability' section on the ASUS Security Advisory for more information.

  • CVE-2024-31163HigJun 14, 2024
    risk 0.47cvss 7.2epss 0.01

    ASUS Download Master has a buffer overflow vulnerability. An unauthenticated remote attacker with administrative privileges can exploit this vulnerability to execute arbitrary system commands on the device.

  • CVE-2024-31162HigJun 14, 2024
    risk 0.47cvss 7.2epss 0.01

    The specific function parameter of ASUS Download Master does not properly filter user input. An unauthenticated remote attacker with administrative privileges can exploit this vulnerability to execute arbitrary system commands on the device.

  • CVE-2024-31161HigJun 14, 2024
    risk 0.47cvss 7.2epss 0.01

    The upload functionality of ASUS Download Master does not properly filter user input. Remote attackers with administrative privilege can exploit this vulnerability to upload any file to any location. They may even upload malicious web page files to the website directory,…

  • CVE-2024-3079HigJun 14, 2024
    risk 0.47cvss 7.2epss 0.01

    Certain models of ASUS routers have buffer overflow vulnerabilities, allowing remote attackers with administrative privileges to execute arbitrary commands on the device.

  • CVE-2024-0401HigMay 20, 2024
    risk 0.47cvss 7.2epss 0.01

    ASUS routers supporting custom OpenVPN profiles are vulnerable to a code execution vulnerability. An authenticated and remote attacker can execute arbitrary operating system commands by uploading a crafted OVPN profile. Known affected routers include ASUS ExpertWiFi, ASUS…

Page 4 of 8