Asus Asus

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in any Asus product.

RSS Feeds for Asus security vulnerabilities

Create a CVE RSS feed including security vulnerabilities found in Asus products with stack.watch. Just hit watch, then grab your custom RSS feed url.

Products by Asus Sorted by Most Security Vulnerabilities since 2018

Asus Armoury Crate14 vulnerabilities

Asus Router12 vulnerabilities

Asus Download Master5 vulnerabilities

Asus Rt N10lx Firmware3 vulnerabilities

Asus Business Manager3 vulnerabilities

Asus Rt Ac68u Firmware3 vulnerabilities

Asus Rt N12 B12 vulnerabilities

Asus Rt Ax552 vulnerabilities

Asus Aura Sync2 vulnerabilities

Asus Rt N12 B1 Firmware2 vulnerabilities

Asus Business Manager2 vulnerabilities

Asus Ai Suite 32 vulnerabilities

Asus Rt Ac67u1 vulnerability

Asus Rt Ac86u1 vulnerability

Asus Rt Ac68u1 vulnerability

Asus Rt Ac86u Firmware1 vulnerability

Asus Rt Ac68r1 vulnerability

Asus Rt Ac87u Firmware1 vulnerability

Asus Rt Ac88u1 vulnerability

Asus Rt Ax30001 vulnerability

Asus Rt Ax3000 Firmware1 vulnerability

Asus Rt Ac68p1 vulnerability

Asus Router App1 vulnerability

Asus Rt Ax55 Firmware1 vulnerability

Asus Rt Ax58u1 vulnerability

Asus Rt Ax86 Series1 vulnerability

Asus Rt Ax88u1 vulnerability

Asus Rt Ax88u Firmware1 vulnerability

Asus Rt Ax92u Firmware1 vulnerability

Asus Rt N12e Firmware1 vulnerability

Asus Zenwifi Xt81 vulnerability

Asus Dsl1 vulnerability

Asus 4g Ac68u Firmware1 vulnerability

Asus Ai Suite1 vulnerability

Asusptpfilter1 vulnerability

Asus Driver Headset1 vulnerability

Asus Driverhub1 vulnerability

Asus Rt Ac66u B11 vulnerability

Asus Expertwifi1 vulnerability

Asus Gamesdk1 vulnerability

Asus Gt Ac2900 Firmware1 vulnerability

Asus Live Update1 vulnerability

Asus 4g Ac68u1 vulnerability

Asus Rt Ac19001 vulnerability

Asus Rt Ac1900u1 vulnerability

Asus Rt Ac29001 vulnerability

Asus Rt Ac51u Firmware1 vulnerability

Known Exploited Asus Vulnerabilities

The following Asus vulnerabilities have been marked by CISA as Known to be Exploited by threat actors.

Title Description Added
ASUS Live Update Embedded Malicious Code Vulnerability ASUS Live Update contains an embedded malicious code vulnerability client were distributed with unauthorized modifications introduced through a supply chain compromise. The modified builds could cause devices meeting specific targeting conditions to perform unintended actions. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.
CVE-2025-59374 Exploit Probability: 1.1%
December 17, 2025
ASUS Routers Improper Authentication Vulnerability ASUS Lyra Mini and ASUS GT-AC2900 devices contain an improper authentication vulnerability that allows an attacker to gain unauthorized access to the administrative interface. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.
CVE-2021-32030 Exploit Probability: 99.4%
June 2, 2025
ASUS RT-AX55 Routers OS Command Injection Vulnerability ASUS RT-AX55 devices contain a OS command injection vulnerability that could allow a remote, authenticated attacker to execute arbitrary commands.
CVE-2023-39780 Exploit Probability: 33.6%
June 2, 2025

The vulnerability CVE-2021-32030: ASUS Routers Improper Authentication Vulnerability is in the top 1% of the currently known exploitable vulnerabilities. The vulnerability CVE-2023-39780: ASUS RT-AX55 Routers OS Command Injection Vulnerability is in the top 5% of the currently known exploitable vulnerabilities.

By the Year

In 2026 there have been 25 vulnerabilities in Asus. Last year, in 2025 Asus had 21 security vulnerabilities published. That is, 4 more vulnerabilities have already been reported in 2026 as compared to last year.




Year Vulnerabilities Average Score
2026 25 0.00
2025 21 0.00
2024 15 6.81
2023 15 7.64
2022 13 7.52
2021 4 7.60
2020 3 5.30
2019 3 9.30
2018 2 9.80

It may take a day or so for new Asus vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Asus Security Vulnerabilities

CVE Date Vulnerability Products
CVE-2019-25764 Jul 17, 2026
Local Privilege Escalation in ASUS AuraSync Driver via unchecked IOCTL **UNSUPPORTED WHEN ASSIGNED**  Exposed IOCTL with Insufficient Access Control in the ASUS AURA SYNC driver allows a local user to bypass the driver's verification and invoke arbitrary IOCTLs, resulting in privilege escalation. Refer to the 'End-of-Life Notice and Driver Update for Legacy ASUS Drivers ' section on the ASUS Security Advisory for more information.
Aura Sync
CVE-2026-13385 Jul 15, 2026
ASUS Router Remote MITM Arbitrary Code via Improper Cert/Integrity Validation An Improper Validation of Integrity Check Value and Improper Certificate Validation in certain ASUS router models allows a remote man-in-the-middle(MITM) user to make the router download and execute arbitrary command via a spoofed server. Refer to the '  Security Update for ASUS Router Firmware  ' section on the ASUS Security Advisory for more information.
Router
CVE-2026-15029 Jul 15, 2026
ASUS System Control Interface v3 Local Admin IOCTL Pointer Deref Untrusted Pointer Dereference in ASUS System Control Interface v3, ASUS System Control Interface, and ASUS Business Manager allows a local administrator to perform arbitrary physical memory read and write operations via crafted IOCTL requests to the driver, bypassing OS-enforced memory protections. Refer to the '  Security Update for ASUS System Control Interface  ' section on the ASUS Security Advisory for more information.
System Control Interface V3
System Control Interface
Business Manager
And others...
CVE-2026-15030 Jul 15, 2026
OOB Read in ASUS System Control Interface v3 via crafted IOCTL Out-of-bounds Read in ASUS System Control Interface v3, ASUS System Control Interface, and ASUS Business Manager allows a local administrator to read memory regions beyond the intended firmware boundary by supplying a crafted IOCTL request that bypasses the validation. Refer to the ' Security Update for ASUS System Control Interface  ' section on the ASUS Security Advisory for more information.
System Control Interface V3
System Control Interface
Business Manager
And others...
CVE-2026-13585 Jul 15, 2026
ASUS System Control Interface Driver Unbounded Resource Allocation & Leakage Allocation of Resources Without Limits and Throttling and Sensitive Information in Resource Not Removed Before Reuse in the ASUS System Control Interface driver and ASUS Business Manager allow a local administrator to disclose sensitive information via crafted IOCTL requests, which, in severe cases, may lead to a Denial of Service (DoS) on the system. Refer to the '  Security Update for ASUS System Control Interface  ' section on the ASUS Security Advisory for more information.
System Control Interface V3
System Control Interface
Business Manager
And others...
CVE-2026-8920 Jul 15, 2026
Aura Wallpaper Service RCE via External File Path Control Improper Restriction of Communication Channel to Intended Endpoints and External Control of File Name or Path in Aura Wallpaper Service allow a local user to perform file operations by sending crafted commands containing an arbitrary file path and bypassing the services path restrictions . On specific models , this can also cause a single feature to become unavailable . Refer to the ' Security Update for Aura Wallpaper Service ' section on the ASUS Security Advisory for more information.
Aura Wallpaper Service
CVE-2026-8919 Jul 15, 2026
ASUS GameSDK Cross-Domain Policy Enables Remote NTLM Hash Leak Permissive Cross-domain Security Policy with Untrusted Domains in ASUS GameSDK allows a remote user to obtain a local users NTLM hash by convincing the user to visit a crafted web page that sends a request containing a UNC path to the applications local service endpoint. This can result in information disclosure or data tampering, may cause GameSDK to become unavailable, and may also enable access to the victims information on other services. Refer to the ' Security Update for ASUS GameSDK  ' section on the ASUS Security Advisory for more information.
Gamesdk
CVE-2026-11851 Jul 15, 2026
ASUS Router SQLi via Web Mgr Auth Bypass Disclosure Improper Neutralization of Special Elements used in an SQL Command ("SQL Injection") in the web management interface of certain ASUS router models allows a remote authenticated user to disclose confidential information via a crafted request that bypasses existing input validation Refer to the '  Security Update for ASUS Router Firmware ' section on the ASUS Security Advisory for more information.
Router
CVE-2022-4989 Jul 03, 2026
Easily PrivEsc in ASUS AI Suite 3 Driver via IOCTL Quantity Validation Error ** UNSUPPORTED WHEN ASSIGNED ** Improper Validation of Specified Quantity in Input in the ASUS AI Suite 3 driver allows a local user to access unintended memory regions via crafted IOCTL requests, leading to privilege escalation. Refer to the 'End-of-Life Notice and Driver Update for Legacy ASUS Drivers ' section on the ASUS Security Advisory for more information.
Ai Suite 3
CVE-2022-4990 Jul 03, 2026
ASUS AI Suite 3: Improper Quantity Validation via IOCTL for Priv Escalation ** UNSUPPORTED WHEN ASSIGNED ** Improper Validation of Specified Quantity in Input in the ASUS AI Suite 3 driver allows a local user to bypass security validation and access restricted memory blocks via crafted IOCTL requests, leading to privilege escalation. Refer to the 'End-of-Life Notice and Driver Update for Legacy ASUS Drivers ' section on the ASUS Security Advisory for more information.
Ai Suite 3
CVE-2026-8921 Jul 03, 2026
ASUS Business Manager External Control Path via IPC (CVE-2026-8921) External Control of File Name or Path vulnerability in ASUS Business Manager allows a local user to execute arbitrary code with SYSTEM privileges via a tampered IPC message. Refer to the ' Security Update for ASUS Business Manager ' section on the ASUS Security Advisory for more information.
Asus Business Manager
CVE-2026-12960 Jul 03, 2026
Improper Export: ASUS Router App Intent opens URL (CVE-2026-12960) An Improper Export of Android Application Components vulnerability in ASUS Router App allows a third-party application on the same device to send a crafted Intent that causes ASUS Router App to open an specified URL. Refer to the ' Security Update for ASUS Router Android App ' section on the ASUS Security Advisory for more information.
Router App
CVE-2026-8918 Jun 22, 2026
Arbitrary Mem RW via Input Bypass in ASUS Armoury Crate A permissive list of allowed inputs in ASUS Armoury Crate allows a local administrator to perform arbitrary memory read/write operations or cause a system crash (BSOD) by bypassing the validation mechanism.Refer to the ' Security Update for Armoury Crate App ' section on the ASUS Security Advisory for more information.
Armoury Crate
CVE-2026-7480 May 29, 2026
ASUS System Control Interface Local Priv Esc via RPC Permission Bypass An Incorrect Permission Assignment for Critical Resource vulnerability in ASUS System Control Interface allows a local user to elevate privileges to SYSTEM and execute arbitrary code via a crafted RPC call that bypass the validation mechanism. Refer to the 'Security Update for ASUS System Control Interface' section on the ASUS Security Advisory for more information.
System Control Interface
CVE-2026-8070 May 29, 2026
Armoury Crate Local Permission Elevation Bypass (CVE-2026-8070) Incorrect permission assignment for a critical resource in Armoury Crate allows a local user to bypass the drivers validation mechanism, resulting in unauthorized read and write access to physical memory.Refer to the '  Security Update for Armoury Crate App   ' section on the ASUS Security Advisory for more information.
Armoury Crate
CVE-2026-3508 May 08, 2026
ASUS System Control Interface IOCTL OOB Read Crash An Out-of-bounds Read vulnerability in the IOCTL handler in ASUS System Control Interface allows a local user to cause system crash (BSOD) via a read size that exceeds the buffer size.Refer to the ' Security Update for MyASUS ' section on the ASUS Security Advisory for more information.
Asus System Control Interface
CVE-2026-6737 May 08, 2026
Local User Bypass via Exposed IOCTL in Asus Precision Touchpad An Exposed IOCTL with Insufficient Access Control vulnerability in AsusPTPFilter allows a local user to bypass driver security mechanisms and obtain restricted touchpad information or render the touchpad unusable via crafted IOCTL requests.Refer to the ' Security Update for ASUS Precision Touchpad ' section on the ASUS Security Advisory for more information.
Asusptpfilter
CVE-2026-3428 Apr 16, 2026
ASUS Member Center: TOC-TOU Privilege Escalation via Unchecked Update A Download of Code Without Integrity Check vulnerability in the update modules in ASUS Member Center() allows a local user to achieve privilege escalation to Administrator via exploitation of a Time-of-check Time-of-use (TOC-TOU) during the update process, where an unexpected payload is substituted for a legitimate one immediately after download, and subsequently executed with administrative privileges upon user consent. Refer to the 'Security Update for ASUS Member Center' section on the ASUS Security Advisory for more information.
CVE-2026-1880 Apr 16, 2026
Privilege Escalation via Permission Misassignment in ASUS DriverHub Update An Incorrect Permission Assignment for Critical Resource vulnerability in the ASUS DriverHub update process allows privilege escalation due to improper protection of required execution resources during the validation phase, permitting a local user to make unprivileged modifications. This allows the altered resource to pass system checks and be executed with elevated privileges upon a user-initiated update. Refer to the 'Security Update for ASUS DriverHub' section on the ASUS Security Advisory for more information.
Driverhub
CVE-2025-15101 Mar 26, 2026
ASUS Router Web UI CSRF Enables Authenticated Privilege Actions An OS command injection vulnerability in the web management interface of certain ASUS router models allows remote authenticated administrators to execute arbitrary system commands via a crafted parameter. Refer to the 'Security Update for ASUS Router Firmware' section on the ASUS Security Advisory for more information.
Router
CVE-2025-15038 Mar 12, 2026
OOB Read in ASUS Business System Control Intf Driver An Out-of-Bounds Read vulnerability exists in the ASUS Business System Control Interface driver. This vulnerability can be triggered by an unprivileged local user sending a specially crafted IOCTL  request, potentially leading to a disclosure of kernel information or a system crash. Refer to the "Security Update for ASUS  Business System Control Interface" section on the ASUS Security Advisory for more information.
Asus Business System Control Interface
CVE-2026-1878 Mar 12, 2026
ASUS ROG Driver Race Condition Priv Escalation An Insufficient Integrity Verification vulnerability in the ASUS ROG peripheral driver installation process allows privilege escalation to SYSTEM. The vulnerability is due to improper access control on the installation directory, which enables the exploitation of a race condition where the legitimate installer is substituted with an unexpected payload immediately after download, resulting in arbitrary code execution. Refer to the "Security Update for ASUS ROG peripheral driver" section on the ASUS Security Advisory for more information.
Driver Keyboard Mouse
Driver Headset
CVE-2025-15037 Mar 12, 2026
ASUS Business System Control Interface IOCTL Perm Escalation An Incorrect Permission Assignment vulnerability exists in the ASUS Business System Control Interface driver. This vulnerability can be triggered by an unprivileged local user sending a specially crafted IOCTL request, potentially leading to unauthorized access to sensitive hardware resources and kernel information disclosure. Refer to the "ASUS Business System Control Interface" section on the ASUS Security Advisory for more information.
Asus Business System Control Interface
CVE-2025-13348 Feb 02, 2026
ASUS Secure Delete Driver Local File Creation via Improper Access Control An improper access control vulnerability exists in ASUS Secure Delete Driver of ASUS Business Manager. This vulnerability can be triggered by a local user sending a specially crafted request, potentially leading to the creation of arbitrary files in a specified path. Refer to the "Security Update for ASUS Business Manager" section on the ASUS Security Advisory for more information.
Asus Business Manager
CVE-2025-12793 Jan 06, 2026
Uncontrolled DLL Load in ASUS SoftwareManagerAgent An uncontrolled DLL loading path vulnerability exists in AsusSoftwareManagerAgent. A local attacker may influence the application to load a DLL from an attacker-controlled location, potentially resulting in arbitrary code execution. Refer to the ' Security Update for MyASUS' section on the ASUS Security Advisory for more information.
CVE-2025-59374 Dec 17, 2025
ASUS Live Update Client Supply-Chain Compromise: Unauthorized Modifications "UNSUPPORTED WHEN ASSIGNED" Certain versions of the ASUS Live Update client were distributed with unauthorized modifications introduced through a supply chain compromise. The modified builds could cause devices meeting specific targeting conditions to perform unintended actions. Only devices that met these conditions and installed the compromised versions were affected. The Live Update client has already reached End-of-Support (EOS) in October 2021, and no currently supported devices or products are affected by this issue.
Live Update
CVE-2025-11775 Dec 17, 2025
ASUS asComSvc OOB Read in Armoury Crate An out-of-bounds read vulnerability has been identified in the asComSvc service. This vulnerability can be triggered by sending specially crafted requests, which may lead to a service crash or partial loss of functionality. This vulnerability only affects ASUS motherboard series products. Refer to the 'Security Update for Armoury Crate App' section on the ASUS Security Advisory for more information.
Armoury Crate
CVE-2025-11901 Dec 17, 2025
Uncontrolled Resource Consumption in ASUS UEFI Firmware via DMA An uncontrolled resource consumption vulnerability affects certain ASUS motherboards using Intel B460, B560, B660, B760, H410, H510, H610, H470, Z590, Z690, Z790, W480, W680 series chipsets. Exploitation requires physical access to internal expansion slots to install a specially crafted device and supporting software utility, and may lead to uncontrolled resource consumption that increases the risk of unauthorized direct memory access (DMA). Refer to the 'Security Update for UEFI firmware' section on the ASUS Security Advisory for more information.
CVE-2025-59372 Nov 25, 2025
ASUS Router Firmware Path Traversal for Authenticated File Write A path traversal vulnerability has been identified in certain router models. A remote, authenticated attacker could exploit this vulnerability to write files outside the intended directory, potentially affecting device integrity. Refer to the 'Security Update for ASUS Router Firmware' section on the ASUS Security Advisory for more information.
Router
CVE-2025-59371 Nov 25, 2025
AUTH Bypass in Asus Router IFTTT Integration Remote Auth Attacker Access An authentication bypass vulnerability has been identified in the IFTTT integration feature. A remote, authenticated attacker could leverage this vulnerability to potentially gain unauthorized access to the device. This vulnerability does not affect Wi-Fi 7 series models. Refer to the 'Security Update for ASUS Router Firmware' section on the ASUS Security Advisory for more information.
Router
CVE-2025-59370 Nov 25, 2025
Command Injection in ASUS bwdpi Router Firmware A command injection vulnerability has been identified in bwdpi. A remote, authenticated attacker could leverage this vulnerability to potentially execute arbitrary commands, leading to the device executing unintended instructions. Refer to the 'Security Update for ASUS Router Firmware' section on the ASUS Security Advisory for more information.
Router
CVE-2025-59369 Nov 25, 2025
CVE-2025-59369: Authenticated SQLi in bwdpi of ASUS Router A SQL injection vulnerability has been identified in bwdpi. A remote, authenticated attacker could leverage this vulnerability to potentially execute arbitrary SQL queries, leading to unauthorized data access. Refer to the 'Security Update for ASUS Router Firmware' section on the ASUS Security Advisory for more information.
Router
CVE-2025-59368 Nov 25, 2025
Integer Underflow in Aicloud (ASUS Router) Enables DoS An integer underflow vulnerability has been identified in Aicloud. An authenticated attacker may trigger this vulnerability by sending a crafted request, potentially impacting the availability of the device. Refer to the ' Security Update for ASUS Router Firmware' section on the ASUS Security Advisory for more information.
Router
CVE-2025-12003 Nov 25, 2025
ASUS Router WebDAV Path Traversal VULN Affects Device Integrity A path traversal vulnerability has been identified in WebDAV, which may allow unauthenticated remote attackers to impact the integrity of the device. Refer to the ' Security Update for ASUS Router Firmware' section on the ASUS Security Advisory for more information.
Router
CVE-2025-59365 Nov 25, 2025
Auth Stack Buffer Overflow in ASUS Router Firmware A stack buffer overflow vulnerability has been identified in certain router models. An authenticated attacker may trigger this vulnerability by sending a crafted request, potentially impacting the availability of the device. Refer to the ' Security Update for ASUS Router Firmware' section on the ASUS Security Advisory for more information.
Router
CVE-2025-59366 Nov 25, 2025
Auth Bypass in ASUS AiCloud via Samba Functionality An authentication-bypass vulnerability exists in AiCloud. This vulnerability can be triggered by an unintended side effect of the Samba functionality, potentially leading to allow execution of specific functions without proper authorization. Refer to the Security Update for ASUS Router Firmware section on the ASUS Security Advisory for more information.
Router
CVE-2025-59373 Nov 25, 2025
Local Privilege Escalation in ASUS SysCtrl Interface Restore Mechanism A local privilege escalation vulnerability exists in the restore mechanism of ASUS System Control Interface. It can be triggered when an unprivileged actor copies files without proper validation into protected system paths, potentially leading to arbitrary files being executed as SYSTEM. For more information, please refer to section Security Update for MyASUS in the ASUS Security Advisory.
CVE-2025-59367 Nov 13, 2025
ASUS DSL Series Router Auth Bypass Remote Access An authentication bypass vulnerability has been identified in certain DSL series routers, may allow remote attackers to gain unauthorized access into the affected system. Refer to the 'Security Update for DSL Series Router' section on the ASUS Security Advisory for more information.
Dsl
CVE-2025-9338 Nov 06, 2025
ASUS Armoury Crate AsIO3.sys Local Privilege Escalation via Buffer Overflow A improper restriction of operations within the bounds of a memory buffer exists in AsIO3.sys driver. This vulnerability can be triggered by manually executing a specially crafted process, potentially leading to local privilage escalation. For additional information, please refer to the 'Security Update for Armoury Crate App' section of the ASUS Security Advisory.
Armoury Crate
CVE-2025-9337 Oct 13, 2025
ASUS AsIO3.sys NPE Crash in Armoury Crate A null pointer dereference has been identified in the AsIO3.sys driver. The vulnerability can be triggered by a specially crafted input, which may lead to a system crash (BSOD). Refer to the 'Security Update for Armoury Crate App' section on the ASUS Security Advisory for more information.
Armoury Crate
CVE-2025-9336 Oct 13, 2025
Buffer Overflow in AsIO3.sys driver of Asus Armoury Crate A stack buffer overflow has been identified in the AsIO3.sys driver. This vulnerability can be triggered by input manipulation, may leading to a system crash (BSOD) or other potentially undefined execution. Refer to the 'Security Update for Armoury Crate App' section on the ASUS Security Advisory for more information.
Armoury Crate
CVE-2025-9968 Oct 13, 2025
Armoury Crate UnifyScanner Link-Following PrivEsc Vulnerability A link following vulnerability exists in the UnifyScanner component of Armoury Crate. This vulnerability may be triggered by creating a specially crafted junction, potentially leading to local privilege escalation. For more information, please refer to section 'Security Update for Armoury Crate App' in the ASUS Security Advisory.
Armoury Crate
CVE-2025-3464 Jun 16, 2025
Armoury Crate Race Condition TTOU Auth Bypass (CVE-2025-3464) A race condition vulnerability exists in Armoury Crate. This vulnerability arises from a Time-of-check Time-of-use issue, potentially leading to authentication bypass. Refer to the 'Security Update for Armoury Crate App' section on the ASUS Security Advisory for more information.
Armoury Crate
CVE-2025-1533 May 12, 2025
ASIO3.sys Buffer Overflow in ASUS Armoury Crate Driver A stack buffer overflow has been identified in the AsIO3.sys driver. This vulnerability can be triggered by input manipulation, may leading to a system crash (BSOD) or other potentially undefined execution. Refer to the 'Security Update for Armoury Crate App' section on the ASUS Security Advisory for more information.
Armoury Crate
CVE-2025-2492 Apr 18, 2025
ASUS AiCloud Improper Auth Flaw An improper authentication control vulnerability exists in AiCloud. This vulnerability can be triggered by a crafted request, potentially leading to unauthorized execution of functions. Refer to the 'ASUS Router AiCloud vulnerability' section on the ASUS Security Advisory for more information.
Router
CVE-2024-12957 Jan 23, 2025
Arbitrary File Deletion via File Handling in Armoury Crate A file handling command vulnerability in certain versions of Armoury Crate may result in arbitrary file deletion. Refer to the '01/23/2025 Security Update for Armoury Crate App' section on the ASUS Security Advisory for more information.
Armoury Crate
CVE-2024-31163 Jun 14, 2024
ASUS Download Master Buffer Overflow Enables Remote Code Exec ASUS Download Master has a buffer overflow vulnerability. An unauthenticated remote attacker with administrative privileges can exploit this vulnerability to execute arbitrary system commands on the device.
Download Master
CVE-2024-31162 Jun 14, 2024
CVE-2024-31162: ASUS DM Unauth Remote Cmd Exec via Unfiltered Param The specific function parameter of ASUS Download Master does not properly filter user input. An unauthenticated remote attacker with administrative privileges can exploit this vulnerability to execute arbitrary system commands on the device.
Download Master
CVE-2024-31161 Jun 14, 2024
ASUS Download Master UPLOAD flaw: Arbitrary File Upload with Admin Privileges The upload functionality of ASUS Download Master does not properly filter user input. Remote attackers with administrative privilege can exploit this vulnerability to upload any file to any location. They may even upload malicious web page files to the website directory, allowing arbitrary system commands to be executed upon browsing the webpage.
Download Master
CVE-2024-31160 Jun 14, 2024
ASUS DM Stored XSS via unsanitized param The parameter used in the certain page of ASUS Download Master is not properly filtered for user input. A remote attacker with administrative privilege can insert JavaScript code to the parameter for Stored Cross-site scripting attacks.
Download Master
Built by Foundeo Inc., with data from the National Vulnerability Database (NVD). Privacy Policy. Use of this site is governed by the Legal Terms
Disclaimer
CONTENT ON THIS WEBSITE IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. Always check with your vendor for the most up to date, and accurate information.