Router
ASUS · 20 CVEs
Improper Neutralization of Input During Web Page Generation (“Cross-site Scripting”) in ASUS router modules allows a re…
Oct 7, 2026
A predictable seed in the pseudo-random number generator (PRNG) in the IFTTT pairing token generation of the ASUS RT-BE…
Oct 7, 2026
A stack-based buffer overflow in the ASUS router modules allows an authenticated nearby user to execute arbitrary code…
Oct 7, 2026
Insertion of Sensitive Information into Log File in certain ASUS router models allows a remote authenticated attacker t…
Oct 7, 2026
An Active Debug Code vulnerability in certain ASUS router models allows a remote authenticated user, via a crafted HTTP…
Oct 1, 2026
Use of an Externally Controlled Format String in the ASUS Router modules allow a remote authenticated user to execute a…
Oct 1, 2026
An Improper Validation of Integrity Check Value and Improper Certificate Validation in certain ASUS router models allow…
Jul 15, 2026
Improper Neutralization of Special Elements used in an SQL Command ("SQL Injection") in the web management interface of…
Jul 15, 2026
An OS command injection vulnerability in the web management interface of certain ASUS router models allows remote authe…
Mar 26, 2026
A path traversal vulnerability has been identified in certain router models. A remote, authenticated attacker could exp…
Nov 25, 2025
An authentication bypass vulnerability has been identified in the IFTTT integration feature. A remote, authenticated at…
Nov 25, 2025
A command injection vulnerability has been identified in bwdpi. A remote, authenticated attacker could leverage this vu…
Nov 25, 2025
A SQL injection vulnerability has been identified in bwdpi. A remote, authenticated attacker could leverage this vulner…
Nov 25, 2025
An integer underflow vulnerability has been identified in Aicloud. An authenticated attacker may trigger this vulnerabi…
Nov 25, 2025
A path traversal vulnerability has been identified in WebDAV, which may allow unauthenticated remote attackers to impac…
Nov 25, 2025
A stack buffer overflow vulnerability has been identified in certain router models. An authenticated attacker may trigg…
Nov 25, 2025
An authentication-bypass vulnerability exists in AiCloud. This vulnerability can be triggered by an unintended side eff…
Nov 25, 2025
An improper authentication control vulnerability exists in AiCloud. This vulnerability can be triggered by a crafted re…
Apr 18, 2025
An unintended entry point vulnerability has been identified in certain router models, which may allow for arbitrary com…
Jan 2, 2025
An improper input insertion vulnerability in AiCloud on certain router models may lead to arbitrary command execution.…
Jan 2, 2025
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-14911 | Improper Neutralization of Input During Web Page Generation (“Cross-site Scripting”) in ASUS router modules allows a remote attacker to read DOM information, m… | CRITICAL | 0.32% | Oct 7, 2026 |
| CVE-2026-19396 | A predictable seed in the pseudo-random number generator (PRNG) in the IFTTT pairing token generation of the ASUS RT-BE57 router allows an unauthenticated near… | HIGH | 0.13% | Oct 7, 2026 |
| CVE-2026-19386 | A stack-based buffer overflow in the ASUS router modules allows an authenticated nearby user to execute arbitrary code via a crafted configuration file upload… | CRITICAL | 0.19% | Oct 7, 2026 |
| CVE-2026-16528 | Insertion of Sensitive Information into Log File in certain ASUS router models allows a remote authenticated attacker to obtain DDNS credentials from the syste… | HIGH | 0.21% | Oct 7, 2026 |
| CVE-2026-13313 | An Active Debug Code vulnerability in certain ASUS router models allows a remote authenticated user, via a crafted HTTP request, to bypass security mechanisms… | HIGH | 0.68% | Oct 1, 2026 |
| CVE-2026-14157 | Use of an Externally Controlled Format String in the ASUS Router modules allow a remote authenticated user to execute arbitrary commands via a crafted file upl… | CRITICAL | 0.76% | Oct 1, 2026 |
| CVE-2026-13385 | An Improper Validation of Integrity Check Value and Improper Certificate Validation in certain ASUS router models allows a remote man-in-the-middle(MITM) user… | CRITICAL | 0.14% | Jul 15, 2026 |
| CVE-2026-11851 | Improper Neutralization of Special Elements used in an SQL Command ("SQL Injection") in the web management interface of certain ASUS router models allows a rem… | MEDIUM | 0.50% | Jul 15, 2026 |
| CVE-2025-15101 | An OS command injection vulnerability in the web management interface of certain ASUS router models allows remote authenticated administrators to execute arbit… | HIGH | 0.90% | Mar 26, 2026 |
| CVE-2025-59372 | A path traversal vulnerability has been identified in certain router models. A remote, authenticated attacker could exploit this vulnerability to write files o… | MEDIUM | 0.60% | Nov 25, 2025 |
| CVE-2025-59371 | An authentication bypass vulnerability has been identified in the IFTTT integration feature. A remote, authenticated attacker could leverage this vulnerability… | HIGH | 0.75% | Nov 25, 2025 |
| CVE-2025-59370 | A command injection vulnerability has been identified in bwdpi. A remote, authenticated attacker could leverage this vulnerability to potentially execute arbit… | HIGH | 0.98% | Nov 25, 2025 |
| CVE-2025-59369 | A SQL injection vulnerability has been identified in bwdpi. A remote, authenticated attacker could leverage this vulnerability to potentially execute arbitrary… | MEDIUM | 0.45% | Nov 25, 2025 |
| CVE-2025-59368 | An integer underflow vulnerability has been identified in Aicloud. An authenticated attacker may trigger this vulnerability by sending a crafted request, poten… | MEDIUM | 0.39% | Nov 25, 2025 |
| CVE-2025-12003 | A path traversal vulnerability has been identified in WebDAV, which may allow unauthenticated remote attackers to impact the integrity of the device. Refer to… | HIGH | 0.65% | Nov 25, 2025 |
| CVE-2025-59365 | A stack buffer overflow vulnerability has been identified in certain router models. An authenticated attacker may trigger this vulnerability by sending a craft… | MEDIUM | 0.42% | Nov 25, 2025 |
| CVE-2025-59366 | An authentication-bypass vulnerability exists in AiCloud. This vulnerability can be triggered by an unintended side effect of the Samba functionality, potentia… | CRITICAL | 15.76% | Nov 25, 2025 |
| CVE-2025-2492 | An improper authentication control vulnerability exists in AiCloud. This vulnerability can be triggered by a crafted request, potentially leading to unauthoriz… | CRITICAL | 1.11% | Apr 18, 2025 |
| CVE-2024-13062 | An unintended entry point vulnerability has been identified in certain router models, which may allow for arbitrary command execution. Refer to the ' 01/02/202… | HIGH | 0.98% | Jan 2, 2025 |
| CVE-2024-12912 | An improper input insertion vulnerability in AiCloud on certain router models may lead to arbitrary command execution. Refer to the '01/02/2025 ASUS Router AiC… | HIGH | 1.24% | Jan 2, 2025 |
Showing 1 to 20 of 20 CVEs