HomeSecurityASUS warns of critical vulnerability in routers

ASUS warns of critical vulnerability in routers

ASUS has released new firmware to fix nine security vulnerabilities in its routers . Among them is a serious authentication bypass bug that affects devices with AiCloud enabled. This feature allows remote access and turns the router into a personal cloud server, making it particularly vulnerable to attacks when security gaps exist.

 ASUS router vulnerability

The critical CVE-2025-59366 and its origin

According to ASUS, the most serious of the nine vulnerabilities – listed as CVE-2025-59366 – arises as an “unintended side effect of Samba functionality,” allowing certain operations without the necessary authorization to be performed . By combining path traversal with command injection , a remote, unprivileged attacker can gain access with extremely simple attacks, without any user intervention.

See also: Developers left credentials exposed on code generation sites

The nature of the vulnerability makes the problem even more dangerous: attacks can be carried out silently, exploiting basic router processes, which significantly increases the risk for home and corporate networks.

Immediate recommendation: Update firmware without delay

In an official announcement, ASUS urges all users to immediately upgrade the firmware to the latest available version.

Although the company did not release a specific list of affected models, it did mention the firmware versions that fix the issues and provided instructions for users of older devices that are no longer receiving updates.

ASUS warns of critical vulnerability in routers

What should those with older routers disable?

For those who cannot install newer firmware due to end of support, ASUS recommends stopping any Internet-accessible services, including:

  • Remote WAN access
  • Port forwarding
  • DDNS
  • VPN server
  • DMZ
  • Port triggering
  • FTP
  • Remote access to AiCloud

This significantly limits the attack surface and reduces the likelihood of exploiting the CVE-2025-59366 vulnerability.

See also: Vulnerability in Microsoft Update Health Tools configuration allows RCE

The company also recommends using strong, unique passwords for both the router's admin panel and Wi-Fi networks, a basic but often overlooked security practice.

ASUS warns of critical vulnerability in routers

A history of problems: The previous critical gap

The new incident comes just months after the patching of another critical vulnerability, CVE-2025-2492, which exploited specially crafted requests to AiCloud-enabled routers. This bug was used – along with six others – in a large-scale attack dubbed Operation WrtHug.

Network security starts with updating

The ASUS case once again highlights the importance of regularly updating firmware and avoiding using devices that are no longer supported. With the rise of attacks targeting IoT and home devices, routers have become one of the main entry points for cybercriminals.

See also: Vulnerability in HashiCorp Vault allows access to the system without valid credentials

For users, promptly installing the latest updates and disabling dangerous services are essential steps to protect their digital security.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS