Vulnerabilidades en ASUS

168 resultados
Análisis Vexday

Com 137 CVEs catalogadas, o portfólio de vulnerabilidades da ASUS apresenta uma taxa de exploração ativa 3,2 vezes acima da média geral do catálogo CISA KEV, o que indica que, proporcionalmente, as falhas nesse ecossistema têm maior chance de serem weaponizadas do que o esperado para vendors de porte similar. O tipo de falha mais recorrente é CWE-120 (buffer overflow clássico), uma classe de vulnerabilidade que frequentemente viabiliza execução remota de código e que exige atenção reforçada em processos de desenvolvimento e atualização de firmware. A CVE mais perigosa em exploração ativa no momento, CVE-2023-39780, registra um escore EPSS de 0,3216, sinalizando probabilidade relevante de exploração contínua e justificando priorização imediata de correção. Com 12 CVEs críticas e 7 novas entradas nos últimos 90 dias, equipes de segurança que operam ativos ASUS devem manter ciclos de patching curtos e monitorar ativamente indicadores de comprometimento associados às falhas confirmadas no KEV.

CVE-2022-26672HIGHASUS WebStorage - Use of Hard-coded CredentialsEPSS 1.2%CVE-2025-59374CRITICAL"UNSUPPORTED WHEN ASSIGNED" Certain versions of the ASUS Live Update client were distributed with unauthorized modifications introduced throEPSS 1.2%KEVCVE-2021-28196MEDIUMASUS BMC's firmware: buffer overflow - Generate SSL certificate functionEPSS 1.2%CVE-2021-28187MEDIUMASUS BMC's firmware: buffer overflow - Generate new SSL certificateEPSS 1.2%CVE-2021-28190MEDIUMASUS BMC's firmware: buffer overflow - Generate new certificate functionEPSS 1.2%CVE-2025-2492CRITICALAn improper authentication control vulnerability exists in AiCloud. This vulnerability can be triggered by a crafted request, potentially leEPSS 1.1%CVE-2022-38105HIGHAn information disclosure vulnerability exists in the cm_processREQ_NC opcode of Asus RT-AX82U 3.0.0.4.386_49674-ge182230 router's configuraEPSS 1.1%CVE-2023-35087CRITICALASUS RT-AX56U V2 & RT-AC86U - Format String - 2EPSS 1.1%CVE-2022-26669HIGHASUS Control Center - SQL InjectionEPSS 1.1%CVE-2024-3912CRITICALASUS Router - Upload arbitrary firmwareEPSS 1.0%CVE-2024-13062HIGHAn unintended entry point vulnerability has been identified in certain router models, which may allow for arbitrary command execution. ReferEPSS 1.0%CVE-2025-59370HIGHA command injection vulnerability has been identified in bwdpi. A remote, authenticated attacker could leverage this vulnerability to potentEPSS 1.0%CVE-2025-15101HIGHAn OS command injection vulnerability in the web management interface of certain ASUS router models allows remote authenticated administratoEPSS 0.9%CVE-2022-26668HIGHASUS Control Center - Broken Access ControlEPSS 0.9%CVE-2023-28703HIGHASUS RT-AC86U - Buffer OverflowEPSS 0.9%CVE-2023-41349HIGHASUS RT-AX88U - externally-controlled format stringEPSS 0.9%CVE-2016-6557The ASUS RP-AC52 access point, firmware version 1.0.1.1s and possibly earlier, is vulnerable to cross-site request forgeryEPSS 0.9%CVE-2022-25597HIGHASUS RT-AC86U - Command InjectionEPSS 0.9%CVE-2025-59367CRITICALAn authentication bypass vulnerability has been identified in certain DSL series routers, may allow remote attackers to gain unauthorized acEPSS 0.9%CVE-2025-3463CRITICAL"This issue is limited to motherboards and does not affect laptops, desktop computers, or other endpoints." An insufficient validation vulneEPSS 0.8%