Vulnerabilidades en ASUS

168 resultados
Análisis Vexday

Com 137 CVEs catalogadas, o portfólio de vulnerabilidades da ASUS apresenta uma taxa de exploração ativa 3,2 vezes acima da média geral do catálogo CISA KEV, o que indica que, proporcionalmente, as falhas nesse ecossistema têm maior chance de serem weaponizadas do que o esperado para vendors de porte similar. O tipo de falha mais recorrente é CWE-120 (buffer overflow clássico), uma classe de vulnerabilidade que frequentemente viabiliza execução remota de código e que exige atenção reforçada em processos de desenvolvimento e atualização de firmware. A CVE mais perigosa em exploração ativa no momento, CVE-2023-39780, registra um escore EPSS de 0,3216, sinalizando probabilidade relevante de exploração contínua e justificando priorização imediata de correção. Com 12 CVEs críticas e 7 novas entradas nos últimos 90 dias, equipes de segurança que operam ativos ASUS devem manter ciclos de patching curtos e monitorar ativamente indicadores de comprometimento associados às falhas confirmadas no KEV.

CVE-2022-23970HIGHASUS RT-AX56U - Path TraversalEPSS 0.5%CVE-2022-23971HIGHASUS RT-AX56U - Path TraversalEPSS 0.5%CVE-2023-34360HIGHASUS RT-AX88U - Stored XSSEPSS 0.5%CVE-2025-59369MEDIUMA SQL injection vulnerability has been identified in bwdpi. A remote, authenticated attacker could leverage this vulnerability to potentiallEPSS 0.5%CVE-2025-1354MEDIUMA cross-site scripting (XSS) vulnerability in the RT-N10E/ RT-N12E 2.0.0.x firmware . This vulnerability caused by improper input validatioEPSS 0.5%CVE-2022-22054MEDIUMASUS RT-AX56U - Path TraversalEPSS 0.5%CVE-2026-8919HIGHPermissive Cross-domain Security Policy with Untrusted Domains in ASUS GameSDK allows a remote user to obtain a local user’s NTLM hash by coEPSS 0.4%CVE-2025-59365MEDIUMA stack buffer overflow vulnerability has been identified in certain router models. An authenticated attacker may trigger this vulnerabilityEPSS 0.4%CVE-2022-25595MEDIUMASUS RT-AC86U - Improper Input ValidationEPSS 0.4%CVE-2025-59368MEDIUMAn integer underflow vulnerability has been identified in Aicloud. An authenticated attacker may trigger this vulnerability by sending a craEPSS 0.4%CVE-2024-11985MEDIUMAn improper input validation vulnerability leads to device crashes in certain ASUS router models. Refer to the '12/03/2024 ASUS Router ImprEPSS 0.4%CVE-2026-12962MEDIUMA Permissive Cross-domain Security Policy with Untrusted Domains in Armoury Crate allows a remote user to obtain a local user's NTLM hash byEPSS 0.4%CVE-2025-4569HIGHAn insecure sensitive key storage issue was found in MyASUS. potentially allowing unauthorized actor to obtain a token that could be used toEPSS 0.4%CVE-2025-4570MEDIUMAn insecure sensitive key storage issue was found in MyASUS. potentially allowing unauthorized actor to obtain a token that could be used toEPSS 0.4%CVE-2022-38699MEDIUMASUS Armoury Crate Service - Arbitrary File Creation via Elevation of Privilege FlawEPSS 0.3%CVE-2025-1533HIGHA stack buffer overflow has been identified in the AsIO3.sys driver. This vulnerability can be triggered by input manipulation, may leading EPSS 0.3%CVE-2024-31159MEDIUMASUS Download Master - Reflected XSSEPSS 0.3%CVE-2024-31160MEDIUMASUS Download Master - Stored XSSEPSS 0.3%CVE-2026-8918HIGHA permissive list of allowed inputs in ASUS Armoury Crate allows a local administrator to perform arbitrary memory read/write operations or EPSS 0.3%CVE-2022-21933MEDIUMASUS VivoMini/Mini PC - improper input validationEPSS 0.3%