Vulnerabilidades en Asus
168 resultadosAnálisis Vexday
A Asus apresenta 4 vulnerabilidades catalogadas, sendo 2 críticas, porém nenhuma sob ataque ativo no momento. A fraqueza dominante é CWE-119 (estouro de buffer), padrão em produtos embarcados, com risco estabilizado dado que nenhuma foi publicada nos últimos 90 dias.
CVE-2022-22262HIGHASUS Armoury Crate & Aura Creator Installer之ROG Live Service - Improper Link Resolution Before File AccessEPSS 0.3%CVE-2024-55408MEDIUMAn improper access control vulnerability in the AsusSAIO.sys driver may lead to the misuse of software functionality utilizing the driver whEPSS 0.2%CVE-2025-11901HIGHAn uncontrolled resource consumption vulnerability affects certain ASUS motherboards using Intel B460, B560, B660, B760, H410, H510, H610, EPSS 0.2%CVE-2026-75754CRITICALMissing Authentication for Critical Function, Server-Side Request Forgery (SSRF), and Use of Hard-coded Credentials in ASUS Control Center aEPSS 0.2%CVE-2026-19397HIGHMissing authentication for a critical function in ASUS Control Center Express Agent allows an unauthenticated nearby user to control the hosEPSS 0.2%CVE-2021-41289MEDIUMASUS P453UJ - Improper Restriction of Operations within the Bounds of a Memory BufferEPSS 0.2%CVE-2025-9968HIGHA link following vulnerability exists in the UnifyScanner component of Armoury Crate. This vulnerability may be triggered by creating a specEPSS 0.2%CVE-2026-15029HIGHUntrusted Pointer Dereference in ASUS System Control Interface v3, ASUS System Control Interface, and ASUS Business Manager allows a local aEPSS 0.2%CVE-2025-2027MEDIUMA double free vulnerability has been identified in the ASUS System Analysis service. This vulnerability can be triggered by sending speciallEPSS 0.2%CVE-2026-13585HIGHAllocation of Resources Without Limits and Throttling and Sensitive Information in Resource Not Removed Before Reuse in the ASUS System ContEPSS 0.2%CVE-2024-12957HIGHA file handling command vulnerability in certain versions of Armoury Crate may result in arbitrary file deletion.
Refer to the '01/23/2025 SEPSS 0.2%CVE-2026-12960MEDIUMAn Improper Export of Android Application Components vulnerability in ASUS Router App allows a third-party application on the same device toEPSS 0.2%CVE-2026-8921HIGHExternal Control of File Name or Path vulnerability in ASUS Business Manager allows a local user to execute arbitrary code with SYSTEM priviEPSS 0.2%CVE-2025-6398MEDIUMA null pointer dereference vulnerability exists in the IOMap64.sys driver of ASUS AI Suite 3. The vulnerability can be triggered by a speciaEPSS 0.1%CVE-2025-9336MEDIUMA stack buffer overflow has been identified in the AsIO3.sys driver. This vulnerability can be triggered by input manipulation, may leading EPSS 0.1%CVE-2022-4989HIGH** UNSUPPORTED WHEN ASSIGNED ** Improper Validation of Specified Quantity in Input in the ASUS AI Suite 3 driver allows a local user to acceEPSS 0.1%CVE-2026-13385CRITICALAn Improper Validation of Integrity Check Value and Improper Certificate Validation in certain ASUS router models allows a remote man-in-theEPSS 0.1%CVE-2026-1880MEDIUMAn Incorrect Permission Assignment for Critical Resource vulnerability in the ASUS DriverHub update process allows privilege escalation due EPSS 0.1%CVE-2026-3508MEDIUMAn Out-of-bounds Read vulnerability in the IOCTL handler in ASUS System Control Interface allows a local user to cause system crash (BSOD) vEPSS 0.1%CVE-2026-15030MEDIUMOut-of-bounds Read in ASUS System Control Interface v3, ASUS System Control Interface, and ASUS Business Manager allows a local administratoEPSS 0.1%