Asus
Asus Router: vulnerabilities and CVEs
Asus Router has 9 published vulnerabilities, 4 of them in the last 12 months. 3 are rated critical and 0 are listed by CISA as actively exploited.
CVEs9
Last 12 months4
Critical3
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-14157 | Critical (9.4) | — | — | Oct 1, 2026 | Use of an Externally Controlled Format String in the ASUS Router modules allow a remote authenticated user to execute arbitrary commands via a crafted file uploaded through the web management interface. |
| CVE-2026-11851 | Medium (5.9) | 0.50% | — | Jul 15, 2026 | Improper Neutralization of Special Elements used in an SQL Command ("SQL Injection") in the web management interface of certain ASUS router models allows a remote authenticated user to disclose confidential information… |
| CVE-2025-59372 | Medium (6.9) | 0.60% | — | Nov 25, 2025 | A path traversal vulnerability has been identified in certain router models. A remote, authenticated attacker could exploit this vulnerability to write files outside the intended directory, potentially affecting device… |
| CVE-2025-59371 | High (7.5) | 0.75% | — | Nov 25, 2025 | An authentication bypass vulnerability has been identified in the IFTTT integration feature. A remote, authenticated attacker could leverage this vulnerability to potentially gain unauthorized access to the device. This… |
| CVE-2024-13062 | High (7.2) | 0.98% | — | Jan 2, 2025 | An unintended entry point vulnerability has been identified in certain router models, which may allow for arbitrary command execution. Refer to the ' 01/02/2025 ASUS Router AiCloud vulnerability' section on the ASUS… |
| CVE-2024-11985 | Medium (4.4) | 0.36% | — | Dec 4, 2024 | An improper input validation vulnerability leads to device crashes in certain ASUS router models. Refer to the '12/03/2024 ASUS Router Improper Input Validation' section on the ASUS Security Advisory for more… |
| CVE-2024-3912 | Critical (9.8) | 1.0% | — | Jun 14, 2024 | Certain models of ASUS routers have an arbitrary firmware upload vulnerability. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary system commands on the device. |
| CVE-2024-3080 | Critical (9.8) | 43% | — | Jun 14, 2024 | Certain ASUS router models have authentication bypass vulnerability, allowing unauthenticated remote attackers to log in the device. |
| CVE-2024-3079 | High (7.2) | 0.83% | — | Jun 14, 2024 | Certain models of ASUS routers have buffer overflow vulnerabilities, allowing remote attackers with administrative privileges to execute arbitrary commands on the device. |