logo

ASUS warns of new critical auth bypass flaw in AiCloud routers

ID: 948f6724-f54b-50e7-a49d-1b65189562fd

STIX ID: report--948f6724-f54b-50e7-a49d-1b65189562fd

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2025-11-26

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

ASUS released firmware updates addressing nine security vulnerabilities—most notably a critical authentication bypass (CVE-2025-59366) affecting routers with AiCloud, which can be exploited by unauthenticated remote attackers by chaining path traversal and OS command injection. The vendor urges immediate firmware updates and recommends mitigations for end-of-life devices (disabling internet-facing services, strong passwords, etc.); the report also links to a prior exploited flaw (CVE-2025-2492) used in the Operation WrtHug campaign that hijacked thousands of routers potentially used as relay nodes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.