logo

June 20: Improper Authentication Vulnerability in ASUS Routers

ID: a3583a79-d3dc-5262-9375-966b8fc51ad5

STIX ID: report--a3583a79-d3dc-5262-9375-966b8fc51ad5

Feed Name: Censys Blog

Threat Score
70/100

Date Published: 2024-06-20

Date Updated: 2026-04-27

Author: Ivonne Francia; The Censys Research Team

...
...

ASUS routers are affected by CVE-2024-3080 (CWE-287), a critical (CVSS 9.8) improper authentication vulnerability that can allow unauthenticated remote login. Censys observes roughly 147k–157k potentially exposed devices; no proof-of-concept or active exploitation is reported, and ASUS has released firmware updates to remediate the issue.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.