CRITICAL
An authentication-bypass vulnerability exists in AiCloud
Published Nov 25, 2025
9.2
CRITICALCVSS 4.0
EPSS 15.76%
Description
An authentication-bypass vulnerability exists in AiCloud. This vulnerability can be triggered by an unintended side effect of the Samba functionality, potentially leading to allow execution of specific functions without proper authorization.
Refer to the Security Update for ASUS Router Firmware section on the ASUS Security Advisory for more information.
Affected products
-
- Version 3.0.0.4_386StatusaffectedConstraints-
- Version 3.0.0.4_388StatusaffectedConstraints-
- Version 3.0.0.6_102StatusaffectedConstraints-
- Version
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (1)
- https://www.asus.com/content/security-advisory/ vendor-advisory
| Link | Providers | Tags |
|---|---|---|
| https://www.asus.com/content/security-advisory/ | vendor-advisory |
Change history (6)
- CISA ADP
- SSVC technical impact changed from total to
partial total → partial
- SSVC automatable changed from yes to
no yes → no
- SSVC technical impact changed from total to
partial
- CISA ADP
- SSVC technical impact changed from partial to
total partial → total
- SSVC automatable changed from no to
yes no → yes
- SSVC technical impact changed from partial to
total
- CISA ADP
- SSVC technical impact changed from total to
partial total → partial
- SSVC automatable changed from yes to
no yes → no
- SSVC technical impact changed from total to
partial
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner ASUS
Published Nov 25, 2025
Updated Feb 26, 2026
Reserved Sep 15, 2025
Link CVE-2025-59366
CISA Vulnrichment
Updated Nov 25, 2025