ASUS has released security advisories addressing several critical vulnerabilities affecting its routers and PC software. Notably, CVE-2025-59366 is an authentication bypass flaw in the AiCloud feature of ASUS routers, with a CVSS score of 9.4, allowing attackers to execute specific functions without proper authorization due to a Samba-related issue. Additionally, CVE-2025-12003 is a path traversal vulnerability in the WebDAV component of ASUS router firmware, enabling unauthenticated remote attackers to compromise device integrity. Another high-severity issue, CVE-2025-59373, impacts the ASUS System Control Interface Service used by the MyASUS application, allowing local privilege escalation to SYSTEM on Windows devices through a flawed file-restore mechanism. ASUS has provided patches for these vulnerabilities and urges users to update affected devices immediately.
The vulnerabilities impact a wide range of ASUS products, including desktop PCs, laptops, NUC systems, All-in-One machines, and various router models. Attackers exploiting these flaws could gain unauthorized access, escalate privileges, or execute arbitrary code, posing significant risks to both home and enterprise environments. Users are advised to verify their device firmware and software versions and apply the latest security updates via Windows Update or the ASUS Support site to mitigate these threats.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
On November 26, 2025, reporting summarized a set of eight ASUS router vulnerabilities, including the already disclosed critical CVE-2025-59366, and warned of risks such as unauthorized access and possible DDoS-related abuse if left unpatched. The report emphasized urgent remediation by users and administrators.
By November 26, 2025, ASUS had disclosed and patched CVE-2025-59373, a high-severity local privilege escalation flaw in the ASUS System Control Interface Service used by MyASUS. The bug could let a low-privileged user or malware gain SYSTEM privileges, and ASUS released fixed versions 3.1.48.0 for x64 and 4.2.48.0 for ARM.
On November 25, 2025, ASUS disclosed CVE-2025-12003, a high-severity path traversal vulnerability in router WebDAV functionality that could allow unauthenticated remote attackers to compromise device integrity. ASUS recommended firmware updates, security patches, and tighter WebDAV access controls.
On November 25, 2025, ASUS disclosed CVE-2025-59366, a critical authentication-bypass flaw in AiCloud linked to Samba behavior that could let remote attackers perform functions without proper authorization. ASUS advised users to update router firmware and review related security guidance.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcesecurityonline.info
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.