logo

ASUS Vulnerability Disclosure Déjà vu

ID: bff21b23-c492-5887-be99-c5f1c51ee054

STIX ID: report--bff21b23-c492-5887-be99-c5f1c51ee054

Feed Name: HackerOne Blog

Threat Score
55/100

Date Published: 2023-09-11

Date Updated: 2026-06-11

...
...

The HackerOne post recounts a disclosure timeline where a security researcher and CERT/CC repeatedly failed to get a response from ASUS about a critical LiveUpdater vulnerability enabling arbitrary code execution with admin privileges; after months of unsuccessful coordination the issue was publicly disclosed. The piece criticizes ASUS for poor vulnerability handling and customer notification, references a prior FTC settlement, and promotes industry best practices for vulnerability disclosure and coordination.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.