CVE-2025-59367
9.3
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow more
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow less
Source: 54bf65a7-a193-42d2-b1ba-8e150d3c35e1 (Secondary)
Description
An authentication bypass vulnerability has been identified in certain DSL series routers, may allow remote attackers to gain unauthorized access into the affected system. Refer to the 'Security Update for DSL Series Router' section on the ASUS Security Advisory for more information.
Affected (3)
Products: Asus: Dsl Ac51 Firmware, Dsl N16 Firmware, Dsl Ac750 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.1.2.3_1010 |
| Running on/with | Platform Versions |
|---|---|
Asus Dsl Ac51 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.1.2.3_1010 |
| Running on/with | Platform Versions |
|---|---|
Asus Dsl N16 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.1.2.3_1010 |
| Running on/with | Platform Versions |
|---|---|
Asus Dsl Ac750 | All versions |
Related CWEs
CWE-288
Authentication Bypass Using an Alternate Path or Channel
A product requires authentication, but the product has an alternate path or channel that does not require authentication.
CWE-306
Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
References (2)
Timeline
No history available yet.