Router

ASUS · 20 CVEs

CVE-2026-14911
CRITICAL

Improper Neutralization of Input During Web Page Generation (“Cross-site Scripting”) in ASUS router modules allows a re…

Oct 7, 2026

CVE-2026-19396
HIGH

A predictable seed in the pseudo-random number generator (PRNG) in the IFTTT pairing token generation of the ASUS RT-BE…

Oct 7, 2026

CVE-2026-19386
CRITICAL

A stack-based buffer overflow in the ASUS router modules allows an authenticated nearby user to execute arbitrary code…

Oct 7, 2026

CVE-2026-16528
HIGH

Insertion of Sensitive Information into Log File in certain ASUS router models allows a remote authenticated attacker t…

Oct 7, 2026

CVE-2026-13313
HIGH

An Active Debug Code vulnerability in certain ASUS router models allows a remote authenticated user, via a crafted HTTP…

Oct 1, 2026

CVE-2026-14157
CRITICAL

Use of an Externally Controlled Format String in the ASUS Router modules allow a remote authenticated user to execute a…

Oct 1, 2026

CVE-2026-13385
CRITICAL

An Improper Validation of Integrity Check Value and Improper Certificate Validation in certain ASUS router models allow…

Jul 15, 2026

CVE-2026-11851
MEDIUM

Improper Neutralization of Special Elements used in an SQL Command ("SQL Injection") in the web management interface of…

Jul 15, 2026

CVE-2025-15101
HIGH

An OS command injection vulnerability in the web management interface of certain ASUS router models allows remote authe…

Mar 26, 2026

CVE-2025-59372
MEDIUM

A path traversal vulnerability has been identified in certain router models. A remote, authenticated attacker could exp…

Nov 25, 2025

CVE-2025-59371
HIGH

An authentication bypass vulnerability has been identified in the IFTTT integration feature. A remote, authenticated at…

Nov 25, 2025

CVE-2025-59370
HIGH

A command injection vulnerability has been identified in bwdpi. A remote, authenticated attacker could leverage this vu…

Nov 25, 2025

CVE-2025-59369
MEDIUM

A SQL injection vulnerability has been identified in bwdpi. A remote, authenticated attacker could leverage this vulner…

Nov 25, 2025

CVE-2025-59368
MEDIUM

An integer underflow vulnerability has been identified in Aicloud. An authenticated attacker may trigger this vulnerabi…

Nov 25, 2025

CVE-2025-12003
HIGH

A path traversal vulnerability has been identified in WebDAV, which may allow unauthenticated remote attackers to impac…

Nov 25, 2025

CVE-2025-59365
MEDIUM

A stack buffer overflow vulnerability has been identified in certain router models. An authenticated attacker may trigg…

Nov 25, 2025

CVE-2025-59366
CRITICAL

An authentication-bypass vulnerability exists in AiCloud. This vulnerability can be triggered by an unintended side eff…

Nov 25, 2025

CVE-2025-2492
CRITICAL

An improper authentication control vulnerability exists in AiCloud. This vulnerability can be triggered by a crafted re…

Apr 18, 2025

CVE-2024-13062
HIGH

An unintended entry point vulnerability has been identified in certain router models, which may allow for arbitrary com…

Jan 2, 2025

CVE-2024-12912
HIGH

An improper input insertion vulnerability in AiCloud on certain router models may lead to arbitrary command execution.…

Jan 2, 2025

Showing 1 to 20 of 20 CVEs