← Back

Asus

asus

272 CVEs • 897 products

Products (897)

Click to collapse
Toggle
Asuswrt
asuswrt
Rt Ac68u
rt-ac68u
Rt N56u
rt-n56u
Rt N66u
rt-n66u

CVEs (272)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Asus
1Asus Firmware
May 13, 2026
Mar 26, 2026
8.6 HIGH· v4
8.8 HIGH· v3
N/A· v2
An OS command injection vulnerability in the web management interface of certain ASUS router models allows remote authenticated administrators to execute arbitrary system commands via a crafted parameter. Refer to the 'S...Show more
An OS command injection vulnerability in the web management interface of certain ASUS router models allows remote authenticated administrators to execute arbitrary system commands via a crafted parameter. Refer to the 'Security Update for ASUS Router Firmware' section on the ASUS Security Advisory for more information.Show less
1Asus
1Myasus
Jan 28, 2026
Jan 6, 2026
8.5 HIGH· v4
7.8 HIGH· v3
N/A· v2
An uncontrolled DLL loading path vulnerability exists in AsusSoftwareManagerAgent. A local attacker may influence the application to load a DLL from an attacker-controlled location, potentially resulting in arbitrary cod...Show more
An uncontrolled DLL loading path vulnerability exists in AsusSoftwareManagerAgent. A local attacker may influence the application to load a DLL from an attacker-controlled location, potentially resulting in arbitrary code execution. Refer to the ' Security Update for MyASUS' section on the ASUS Security Advisory for more information.Show less
1Asus
1Live Update
Dec 18, 2025
Dec 17, 2025
9.3 CRITICAL· v4
9.8 CRITICAL· v3
N/A· v2
"UNSUPPORTED WHEN ASSIGNED" Certain versions of the ASUS Live Update client were distributed with unauthorized modifications introduced through a supply chain compromise. The modified builds could cause devices meeting s...Show more
"UNSUPPORTED WHEN ASSIGNED" Certain versions of the ASUS Live Update client were distributed with unauthorized modifications introduced through a supply chain compromise. The modified builds could cause devices meeting specific targeting conditions to perform unintended actions. Only devices that met these conditions and installed the compromised versions were affected. The Live Update client has already reached End-of-Support (EOS) in October 2021, and no currently supported devices or products are affected by this issue.Show less
1Asus
1Download Master
Nov 21, 2024
Jun 14, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
The upload functionality of ASUS Download Master does not properly filter user input. Remote attackers with administrative privilege can exploit this vulnerability to upload any file to any location. They may even upload...Show more
The upload functionality of ASUS Download Master does not properly filter user input. Remote attackers with administrative privilege can exploit this vulnerability to upload any file to any location. They may even upload malicious web page files to the website directory, allowing arbitrary system commands to be executed upon browsing the webpage.Show less
1Asus
1Download Master
Nov 21, 2024
Jun 14, 2024
N/A· v4
4.8 MEDIUM· v3
N/A· v2
The parameter used in the certain page of ASUS Download Master is not properly filtered for user input. A remote attacker with administrative privilege can insert JavaScript code to the parameter for Stored Cross-site sc...Show more
The parameter used in the certain page of ASUS Download Master is not properly filtered for user input. A remote attacker with administrative privilege can insert JavaScript code to the parameter for Stored Cross-site scripting attacks.Show less
1Asus
1Download Master
Nov 21, 2024
Jun 14, 2024
N/A· v4
4.8 MEDIUM· v3
N/A· v2
The parameter used in the certain page of ASUS Download Master is not properly filtered for user input. A remote attacker with administrative privilege can insert JavaScript code to the parameter for Reflected Cross-site...Show more
The parameter used in the certain page of ASUS Download Master is not properly filtered for user input. A remote attacker with administrative privilege can insert JavaScript code to the parameter for Reflected Cross-site scripting attacks.Show less
1Asus
1Ai Suite
Apr 18, 2025
May 22, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
An issue in the component AslO3_64.sys of ASUSTeK Computer Inc AISuite3 v3.03.36 3.03.36 allows attackers to escalate privileges and execute arbitrary code via sending crafted IOCTL requests.
1Asus
1Sabertooth X99 Firmware
Apr 18, 2025
May 22, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
An issue in the component AsIO64.sys of ASUSTeK Computer Inc ASUS SABERTOOTH X99 Driver v1.0.1.0 allows attackers to escalate privileges and execute arbitrary code via sending crafted IOCTL requests.
1Asus
1Rt Ax92u Firmware
Aug 12, 2025
May 3, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
ASUS RT-AX92U lighttpd mod_webdav.so SQL Injection Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected ASUS RT-AX92U routers. Authentic...Show more
ASUS RT-AX92U lighttpd mod_webdav.so SQL Injection Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected ASUS RT-AX92U routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the mod_webdav.so module. When parsing a request, the process does not properly validate a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to disclose information in the context of root. Was ZDI-CAN-16078.Show less
1Asus
14g Ac68u Firmware
Apr 28, 2025
Feb 28, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
A Null pointer dereference in usr/sbin/httpd in ASUS AC68U 3.0.0.4.384.82230 allows remote attackers to trigger DoS via network packet.
1Asus
1Armoury Crate
Nov 21, 2024
Jan 19, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
ASUS Armoury Crate has a vulnerability in arbitrary file write and allows remote attackers to access or modify arbitrary files by sending specific HTTP requests without permission.
1Asus
1Rt Ac87u Firmware
Nov 21, 2024
Nov 15, 2023
N/A· v4
9.1 CRITICAL· v3
N/A· v2
An improper access control vulnerability exists in RT-AC87U all versions. An attacker may read or write files that are not intended to be accessed by connecting to a target device via tftp.
1Asus
1Rt Ax55 Firmware
Nov 21, 2024
Nov 3, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
ASUS RT-AX55’s authentication-related function has a vulnerability of insufficient filtering of special characters within its code-authentication module. An authenticated remote attacker can exploit this vulnerability to...Show more
ASUS RT-AX55’s authentication-related function has a vulnerability of insufficient filtering of special characters within its code-authentication module. An authenticated remote attacker can exploit this vulnerability to perform a Command Injection attack to execute arbitrary commands, disrupt the system or terminate services.Show less
1Asus
1Rt Ax55 Firmware
Nov 21, 2024
Nov 3, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
ASUS RT-AX55’s authentication-related function has a vulnerability of insufficient filtering of special characters within its check token module. An authenticated remote attacker can exploit this vulnerability to perform...Show more
ASUS RT-AX55’s authentication-related function has a vulnerability of insufficient filtering of special characters within its check token module. An authenticated remote attacker can exploit this vulnerability to perform a Command Injection attack to execute arbitrary commands, disrupt the system or terminate services.Show less
1Asus
1Rt Ax55 Firmware
Nov 21, 2024
Nov 3, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
ASUS RT-AX55’s authentication-related function has a vulnerability of insufficient filtering of special characters within its token-refresh module. An authenticated remote attacker can exploit this vulnerability to perfo...Show more
ASUS RT-AX55’s authentication-related function has a vulnerability of insufficient filtering of special characters within its token-refresh module. An authenticated remote attacker can exploit this vulnerability to perform a Command Injection attack to execute arbitrary commands, disrupt the system or terminate services.Show less
1Asus
1Rt Ax55 Firmware
Nov 21, 2024
Nov 3, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
ASUS RT-AX55’s authentication-related function has a vulnerability of insufficient filtering of special characters within its token-generated module. An authenticated remote attacker can exploit this vulnerability to per...Show more
ASUS RT-AX55’s authentication-related function has a vulnerability of insufficient filtering of special characters within its token-generated module. An authenticated remote attacker can exploit this vulnerability to perform a Command Injection attack to execute arbitrary commands, disrupt the system, or terminate services.Show less
1Asus
1Rt Ax88u Firmware
Nov 21, 2024
Sep 18, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
ASUS router RT-AX88U has a vulnerability of using externally controllable format strings within its Advanced Open VPN function. An authenticated remote attacker can exploit the exported OpenVPN configuration to execute...Show more
ASUS router RT-AX88U has a vulnerability of using externally controllable format strings within its Advanced Open VPN function. An authenticated remote attacker can exploit the exported OpenVPN configuration to execute an externally-controlled format string attack, resulting in sensitivity information leakage, or forcing the device to reset and permanent denial of service. Show less
1Asus
1Rt Ax55 Firmware
Oct 31, 2025
Sep 11, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
On ASUS RT-AX55 3.0.0.4.386.51598 devices, authenticated attackers can perform OS command injection via the /start_apply.htm qos_bw_rulelist parameter. NOTE: for the similar "token-generated module" issue, see CVE-2023-4...Show more
On ASUS RT-AX55 3.0.0.4.386.51598 devices, authenticated attackers can perform OS command injection via the /start_apply.htm qos_bw_rulelist parameter. NOTE: for the similar "token-generated module" issue, see CVE-2023-41345; for the similar "token-refresh module" issue, see CVE-2023-41346; for the similar "check token module" issue, see CVE-2023-41347; and for the similar "code-authentication module" issue, see CVE-2023-41348.Show less
1Asus
3Rt Ac86u Firmware
Rt Ax55 FirmwareRt Ax56u V2 Firmware
Nov 21, 2024
Sep 7, 2023
N/A· v4
7.2 HIGH· v3
N/A· v2
It is identified a format string vulnerability in ASUS RT-AX56U V2’s iperf client function API. This vulnerability is caused by lacking validation for a specific value within its set_iperf3_cli.cgi module. A remote atta...Show more
It is identified a format string vulnerability in ASUS RT-AX56U V2’s iperf client function API. This vulnerability is caused by lacking validation for a specific value within its set_iperf3_cli.cgi module. A remote attacker with administrator privilege can exploit this vulnerability to perform remote arbitrary code execution, arbitrary system operation or disrupt service. Show less
1Asus
3Rt Ac86u Firmware
Rt Ax55 FirmwareRt Ax56u V2 Firmware
Nov 21, 2024
Sep 7, 2023
N/A· v4
7.2 HIGH· v3
N/A· v2
It is identified a format string vulnerability in ASUS RT-AX56U V2’s General function API. This vulnerability is caused by lacking validation for a specific value within its apply.cgi module. A remote attacker with adm...Show more
It is identified a format string vulnerability in ASUS RT-AX56U V2’s General function API. This vulnerability is caused by lacking validation for a specific value within its apply.cgi module. A remote attacker with administrator privilege can exploit this vulnerability to perform remote arbitrary code execution, arbitrary system operation or disrupt service. Show less