Back

CRITICAL

An authentication-bypass vulnerability exists in AiCloud

Published Nov 25, 2025

Description

An authentication-bypass vulnerability exists in AiCloud. This vulnerability can be triggered by an unintended side effect of the Samba functionality, potentially leading to allow execution of specific functions without proper authorization.

Refer to the Security Update for ASUS Router Firmware section on the ASUS Security Advisory for more information.

Affected products

Remediation

No remediation recorded yet.

References (1)

Change history (6)
  1. CISA ADP
    • SSVC technical impact changed from total to partial
    • SSVC automatable changed from yes to no
  2. CISA ADP
    • SSVC technical impact changed from partial to total
    • SSVC automatable changed from no to yes
  3. CISA ADP
    • SSVC technical impact changed from total to partial
    • SSVC automatable changed from yes to no
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner ASUS
Published Nov 25, 2025
Updated Feb 26, 2026
Reserved Sep 15, 2025
CISA Vulnrichment
Updated Nov 25, 2025
NVD
Status Deferred
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a