VYPR

Vendor CVEs

Asus

All CVEs

369 total · sorted by risk
  • CVE-2023-39240HigSep 7, 2023
    risk 0.47cvss 7.2epss 0.01

    It is identified a format string vulnerability in ASUS RT-AX56U V2’s iperf client function API. This vulnerability is caused by lacking validation for a specific value within its set_iperf3_cli.cgi module. A remote attacker with administrator privilege can exploit this…

  • CVE-2023-39239HigSep 7, 2023
    risk 0.47cvss 7.2epss 0.01

    It is identified a format string vulnerability in ASUS RT-AX56U V2’s General function API. This vulnerability is caused by lacking validation for a specific value within its apply.cgi module. A remote attacker with administrator privilege can exploit this vulnerability to…

  • CVE-2023-39238HigSep 7, 2023
    risk 0.47cvss 7.2epss 0.01

    It is identified a format string vulnerability in ASUS RT-AX56U V2. This vulnerability is caused by lacking validation for a specific value within its set_iperf3_svr.cgi module. A remote attacker with administrator privilege can exploit this vulnerability to perform remote…

  • CVE-2023-28703HigJun 2, 2023
    risk 0.47cvss 7.2epss 0.01

    ASUS RT-AC86U’s specific cgi function has a stack-based buffer overflow vulnerability due to insufficient validation for network packet header length. A remote attacker with administrator privileges can exploit this vulnerability to execute arbitrary system commands, disrupt…

  • CVE-2021-40981HigSep 27, 2021
    risk 0.47cvss 7.3epss 0.00

    ASUS ROG Armoury Crate Lite before 4.2.10 allows local users to gain privileges by placing a Trojan horse file in the publicly writable %PROGRAMDATA%\ASUS\GamingCenterLib directory.

  • CVE-2021-28204HigApr 6, 2021
    risk 0.47cvss 7.2epss 0.02

    The specific function in ASUS BMC’s firmware Web management page (Modify user’s information function) does not filter the specific parameter. As obtaining the administrator permission, remote attackers can launch command injection to execute command arbitrary.

  • CVE-2021-28203HigApr 6, 2021
    risk 0.47cvss 7.2epss 0.02

    The Web Set Media Image function in ASUS BMC’s firmware Web management page does not filter the specific parameter. As obtaining the administrator permission, remote attackers can launch command injection to execute command arbitrary.

  • CVE-2018-17022HigSep 13, 2018
    risk 0.47cvss 7.2epss 0.02

    Stack-based buffer overflow on the ASUS GT-AC5300 router through 3.0.0.4.384_32738 allows remote attackers to cause a denial of service (device crash) or possibly have unspecified other impact by setting a long sh_path0 value and then sending an…

  • CVE-2017-5712HigNov 21, 2017
    risk 0.47cvss 7.2epss 0.04

    Buffer overflow in Active Management Technology (AMT) in Intel Manageability Engine Firmware 8.x/9.x/10.x/11.0/11.5/11.6/11.7/11.10/11.20 allows attacker with remote Admin access to the system to execute arbitrary code with AMT execution privilege.

  • CVE-2026-8918HigJun 22, 2026
    risk 0.46cvss —epss 0.00

    A permissive list of allowed inputs in ASUS Armoury Crate allows a local administrator to perform arbitrary memory read/write operations or cause a system crash (BSOD) by bypassing the validation mechanism.Refer to the ' Security Update for Armoury Crate App ' section on the…

  • CVE-2025-11901HigDec 17, 2025
    risk 0.46cvss —epss 0.00

    An uncontrolled resource consumption vulnerability affects certain ASUS motherboards using Intel B460, B560, B660, B760, H410, H510, H610, H470, Z590, Z690, Z790, W480, W680 series chipsets. Exploitation requires physical access to internal expansion slots to install a…

  • CVE-2019-19235HigDec 18, 2019
    risk 0.46cvss 7.0epss 0.00

    AsLdrSrv.exe in ASUS ATK Package before V1.0.0061 (for Windows 10 notebook PCs) could lead to unsigned code execution with no additional execution. The user must put an application at a particular path, with a particular file name.

  • CVE-2018-14980HigApr 25, 2019
    risk 0.46cvss 7.1epss 0.00

    The ASUS ZenFone 3 Max Android device with a build fingerprint of asus/US_Phone/ASUS_X008_1:7.0/NRD90M/US_Phone-14.14.1711.92-20171208:user/release-keys contains the android framework (i.e., system_server) with a package name of android (versionCode=24, versionName=7.0) that has…

  • CVE-2025-15038MedMar 12, 2026
    risk 0.45cvss —epss 0.00

    An Out-of-Bounds Read vulnerability exists in the ASUS Business System Control Interface driver. This vulnerability can be triggered by an unprivileged local user sending a specially crafted IOCTL  request, potentially leading to a disclosure of kernel information or a system…

  • CVE-2025-59372MedNov 25, 2025
    risk 0.45cvss —epss 0.01

    A path traversal vulnerability has been identified in certain router models. A remote, authenticated attacker could exploit this vulnerability to write files outside the intended directory, potentially affecting device integrity. Refer to the 'Security Update for ASUS Router…

  • CVE-2025-59365MedNov 25, 2025
    risk 0.45cvss —epss 0.00

    A stack buffer overflow vulnerability has been identified in certain router models. An authenticated attacker may trigger this vulnerability by sending a crafted request, potentially impacting the availability of the device. Refer to the ' Security Update for ASUS Router…

  • CVE-2025-4570MedJul 21, 2025
    risk 0.45cvss —epss 0.00

    An insecure sensitive key storage issue was found in MyASUS. potentially allowing unauthorized actor to obtain a token that could be used to communicate with certain services. Refer to the 'Security Update for for MyASUS' section on the ASUS Security Advisory for more…

  • CVE-2026-19398MedAug 27, 2026
    risk 0.44cvss —epss 0.00

    An out-of-bounds write in the SmiFlash SMM module of ASUS FA507NU and FA507NV BIOS allows a local  administrator to cause a system crash (BSOD) or BIOS corruption via a crafted software SMI (SW SMI) request with an oversized length value.Refer to the '  Security Update for…

  • CVE-2026-3508MedMay 8, 2026
    risk 0.44cvss —epss 0.00

    An Out-of-bounds Read vulnerability in the IOCTL handler in ASUS System Control Interface allows a local user to cause system crash (BSOD) via a read size that exceeds the buffer size.Refer to the ' Security Update for MyASUS ' section on the ASUS Security Advisory for more…

  • CVE-2025-15037MedMar 12, 2026
    risk 0.44cvss —epss 0.00

    An Incorrect Permission Assignment vulnerability exists in the ASUS Business System Control Interface driver. This vulnerability can be triggered by an unprivileged local user sending a specially crafted IOCTL request, potentially leading to unauthorized access to sensitive…

  • CVE-2025-9337MedOct 13, 2025
    risk 0.44cvss —epss 0.00

    A null pointer dereference has been identified in the AsIO3.sys driver. The vulnerability can be triggered by a specially crafted input, which may lead to a system crash (BSOD). Refer to the 'Security Update for Armoury Crate App' section on the ASUS Security Advisory for more…

  • CVE-2025-9336MedOct 13, 2025
    risk 0.44cvss —epss 0.00

    A stack buffer overflow has been identified in the AsIO3.sys driver. This vulnerability can be triggered by input manipulation, may leading to a system crash (BSOD) or other potentially undefined execution. Refer to the 'Security Update for Armoury Crate App' section on the…

  • CVE-2025-6398MedAug 1, 2025
    risk 0.44cvss —epss 0.00

    A null pointer dereference vulnerability exists in the IOMap64.sys driver of ASUS AI Suite 3. The vulnerability can be triggered by a specially crafted input, which may lead to a system crash (BSOD). Refer to the ' Security Update for for AI Suite 3 ' section on the ASUS…

  • CVE-2023-33548MedMay 6, 2024
    risk 0.44cvss 6.8epss 0.01

    Cross Site Scripting (XSS) vulnerability in ASUS RT-AC51U with firmware versions up to and including 3.0.0.4.380.8591 allows attackers to run arbitrary code via the WPA Pre-Shared Key field.

  • CVE-2024-28326MedApr 26, 2024
    risk 0.44cvss 6.8epss 0.00

    Incorrect Access Control in ASUS RT-N12+ B1 and RT-N12 D1 routers allows local attackers to obtain root terminal access via the the UART interface.

  • CVE-2022-21933MedJan 21, 2022
    risk 0.44cvss 6.7epss 0.00

    ASUS VivoMini/Mini PC device has an improper input validation vulnerability. A local attacker with system privilege can use system management interrupt (SMI) to modify memory, resulting in arbitrary code execution for controlling the system or disrupting service.

  • CVE-2021-42055MedOct 18, 2021
    risk 0.44cvss 6.8epss 0.00

    ASUSTek ZenBook Pro Due 15 UX582 laptop firmware through 203 has Insecure Permissions that allow attacks by a physically proximate attacker.

  • CVE-2019-18216MedOct 20, 2019
    risk 0.44cvss 6.8epss 0.00

    The BIOS configuration design on ASUS ROG Zephyrus M GM501GS laptops with BIOS 313 relies on the main battery instead of using a CMOS battery, which reduces the value of a protection mechanism in which booting from a USB device is prohibited. Attackers who have physical laptop…

  • CVE-2018-14712MedMay 13, 2019
    risk 0.43cvss 6.5epss 0.04

    Buffer overflow in appGet.cgi on ASUS RT-AC3200 version 3.0.0.4.382.50010 allows attackers to inject system commands via the "hook" URL parameter.

  • CVE-2017-6547MedMar 9, 2017
    risk 0.43cvss 6.1epss 0.02

    Cross-site scripting (XSS) vulnerability in httpd on ASUS RT-N56U, RT-N66U, RT-AC66U, RT-N66R, RT-AC66R, RT-AC68U, RT-AC68R, RT-N66W, RT-AC66W, RT-AC87R, RT-AC87U, RT-AC51U, RT-AC68P, RT-N11P, RT-N12+, RT-N12E B1, RT-AC3200, RT-AC53U, RT-AC1750, RT-AC1900P, RT-N300, and RT-AC750…

  • CVE-2023-35720MedMay 3, 2024
    risk 0.42cvss 6.5epss 0.01

    ASUS RT-AX92U lighttpd mod_webdav.so SQL Injection Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected ASUS RT-AX92U routers. Authentication is not required to exploit this vulnerability. The…

  • CVE-2021-41437MedSep 26, 2022
    risk 0.42cvss 6.5epss 0.01

    An HTTP response splitting attack in web application in ASUS RT-AX88U before v3.0.0.4.388.20558 allows an attacker to craft a specific URL that if an authenticated victim visits it, the URL will give access to the cloud storage of the attacker.

  • CVE-2022-25595MedApr 7, 2022
    risk 0.42cvss 6.5epss 0.00

    ASUS RT-AC86U has improper user request handling, which allows an unauthenticated LAN attacker to cause a denial of service by sending particular request a server-to-client reply attempt.

  • CVE-2022-22054MedJan 14, 2022
    risk 0.42cvss 6.5epss 0.00

    ASUS RT-AX56U’s login function contains a path traversal vulnerability due to its inadequate filtering for special characters in URL parameters, which allows an unauthenticated local area network attacker to access restricted system paths and download arbitrary files.

  • CVE-2018-14711MedMay 13, 2019
    risk 0.42cvss 6.5epss 0.01

    Missing cross-site request forgery protection in appGet.cgi on ASUS RT-AC3200 version 3.0.0.4.382.50010 allows attackers to cause state-changing actions with specially crafted URLs.

  • CVE-2017-14699MedJan 29, 2018
    risk 0.42cvss 6.5epss 0.01

    Multiple XML external entity (XXE) vulnerabilities in the AiCloud feature on ASUS DSL-AC51, DSL-AC52U, DSL-AC55U, DSL-N55U C1, DSL-N55U D1, DSL-AC56U, DSL-N10_C1, DSL-N12U C1, DSL-N12E C1, DSL-N14U, DSL-N14U-B1, DSL-N16, DSL-N16U, DSL-N17U, DSL-N66U, and DSL-AC750 routers allow…

  • CVE-2017-8878MedMay 10, 2017
    risk 0.42cvss 6.5epss 0.01

    ASUS RT-AC* and RT-N* devices with firmware before 3.0.0.4.380.7378 allow remote authenticated users to discover the Wi-Fi password via WPS_info.xml.

  • CVE-2017-8877MedMay 10, 2017
    risk 0.42cvss 6.5epss 0.01

    ASUS RT-AC* and RT-N* devices with firmware through 3.0.0.4.380.7378 allow JSONP Information Disclosure such as the SSID.

  • CVE-2017-5632MedJan 30, 2017
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered on the ASUS RT-N56U Wireless Router with Firmware 3.0.0.4.374_979. When executing an "nmap -O" command that specifies an IP address of an affected device, one can crash the device's WAN connection, causing disconnection from the Internet, a Denial of…

  • CVE-2021-41289MedNov 15, 2021
    risk 0.41cvss 6.3epss 0.00

    ASUS P453UJ contains the Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability. With a general user’s permission, local attackers can modify the BIOS by replacing or filling in the content of the designated Memory DataBuffer, which causing a…

  • CVE-2024-28325MedApr 26, 2024
    risk 0.40cvss 6.1epss 0.00

    Asus RT-N12+ B1 router stores credentials in cleartext, which could allow local attackers to obtain unauthorized access and modify router settings.

  • CVE-2021-46109MedJan 3, 2022
    risk 0.40cvss 6.1epss 0.01

    Invalid input sanitizing leads to reflected Cross Site Scripting (XSS) in ASUS RT-AC52U_B1 3.0.0.4.380.10931 can lead to a user session hijack.

  • CVE-2021-27404MedFeb 19, 2021
    risk 0.40cvss 6.1epss 0.01

    Askey RTF8115VW BR_SV_g11.11_RTF_TEF001_V6.54_V014 devices allow injection of a Host HTTP header.

  • CVE-2021-27403MedFeb 19, 2021
    risk 0.40cvss 6.1epss 0.01

    Askey RTF8115VW BR_SV_g11.11_RTF_TEF001_V6.54_V014 devices allow cgi-bin/te_acceso_router.cgi curWebPage XSS.

  • CVE-2020-15499MedAug 26, 2020
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered on ASUS RT-AC1900P routers before 3.0.0.4.385_20253. They allow XSS via spoofed Release Notes on the Firmware Upgrade page.

  • CVE-2020-7997MedJan 28, 2020
    risk 0.40cvss 6.1epss 0.01

    ASUS WRT-AC66U 3 RT 3.0.0.4.372_67 devices allow XSS via the Client Name field to the Parental Control feature.

  • CVE-2018-14710MedMay 13, 2019
    risk 0.40cvss 6.1epss 0.05

    Cross-site scripting in appGet.cgi on ASUS RT-AC3200 version 3.0.0.4.382.50010 allows attackers to execute JavaScript via the "hook" URL parameter.

  • CVE-2018-18291MedOct 14, 2018
    risk 0.40cvss 6.1epss 0.01

    A cross site scripting (XSS) vulnerability on ASUS RT-AC58U 3.0.0.4.380_6516 devices allows remote attackers to inject arbitrary web script or HTML via Advanced_ASUSDDNS_Content.asp, Advanced_WSecurity_Content.asp, Advanced_Wireless_Content.asp, Logout.asp, Main_Login.asp,…

  • CVE-2018-17021MedSep 13, 2018
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting (XSS) vulnerability on ASUS GT-AC5300 devices with firmware through 3.0.0.4.384_32738 allows remote attackers to inject arbitrary web script or HTML via the appGet.cgi hook parameter.

  • CVE-2018-0583MedMay 14, 2018
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting vulnerability in ASUS RT-AC1200HP Firmware version prior to 3.0.0.4.380.4180 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Page 5 of 8