Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

ASUS — Vulnerabilities & Security Advisories 175

Browse all 175 CVE security advisories affecting ASUS. AI-powered Chinese analysis, POCs, and references for each vulnerability.

ASUS operates primarily as a manufacturer of consumer electronics, networking hardware, and computer components, serving both individual users and enterprise clients. Its product portfolio, which includes routers, motherboards, and embedded systems, frequently exposes devices to remote code execution, cross-site scripting, and privilege escalation vulnerabilities. These flaws often stem from insecure default configurations, unpatched firmware, and weak authentication mechanisms within web management interfaces. Historically, the company has faced scrutiny over delayed security updates and the persistence of critical defects in widely deployed network equipment. Notable incidents involve compromised routers that allowed attackers to gain administrative access or intercept traffic, highlighting systemic issues in long-term support and secure development practices. With numerous recorded CVEs, ASUS continues to address these legacy weaknesses while navigating the complex security demands of its diverse hardware ecosystem.

CVE ID Title CVSS Severity Published
CVE-2022-26673 ASUS RT-AX88U - Stored XSS — RT-AX88U CWE-79 5.4 Medium 2022-04-22
CVE-2022-26672 ASUS WebStorage - Use of Hard-coded Credentials — WebStorage CWE-798 7.3 High 2022-04-22
CVE-2022-25597 ASUS RT-AC86U - Command Injection — RT-AC86U CWE-78 8.8 High 2022-04-07
CVE-2022-25596 ASUS RT-AC86U - Heap-based buffer overflow — RT-AC86U CWE-787 8.8 High 2022-04-07
CVE-2022-25595 ASUS RT-AC86U - Improper Input Validation — RT-AC86U CWE-20 6.5 Medium 2022-04-07
CVE-2022-23973 ASUS RT-AX56U - Stack overflew — RT-AX56U CWE-787 8.8 High 2022-04-07
CVE-2022-23972 ASUS RT-AX56U - SQL Injection — RT-AX56U CWE-89 8.8 High 2022-04-07
CVE-2022-23971 ASUS RT-AX56U - Path Traversal — RT-AX56U CWE-22 8.1 High 2022-04-07
CVE-2022-23970 ASUS RT-AX56U - Path Traversal — RT-AX56U CWE-22 8.1 High 2022-04-07
CVE-2022-22262 ASUS Armoury Crate & Aura Creator Installer之ROG Live Service - Improper Link Resolution Before File Access — Armoury Crate & Aura Creator Installer (ROG Live Service) CWE-59 7.7 High 2022-03-01
CVE-2022-21933 ASUS VivoMini/Mini PC - improper input validation — VC65-C1 CWE-20 6.7 Medium 2022-01-21
CVE-2022-22054 ASUS RT-AX56U - Path Traversal — RT-AX56U CWE-22 6.5 Medium 2022-01-14
CVE-2021-44158 ASUS RT-AX56U Router - Stack-based buffer overflow — RT-AX56U CWE-121 8.0 High 2022-01-03
CVE-2021-41289 ASUS P453UJ - Improper Restriction of Operations within the Bounds of a Memory Buffer — P453UJ BIOS CWE-119 6.3 Medium 2021-11-15
CVE-2021-37910 ASUS GT-AXE11000, RT-AX3000, RT-AX55, RT-AX58U, TUF-AX3000 - Improper Authentication — GT-AXE11000 CWE-799 3.7 Low 2021-11-12
CVE-2021-28209 ASUS BMC's firmware: path traversal - Delete video file function — BMC firmware for ASMB9-iKVM CWE-22 4.9 Medium 2021-04-06
CVE-2021-28208 ASUS BMC's firmware: path traversal - Get video file function — BMC firmware for ASMB9-iKVM CWE-22 4.9 Medium 2021-04-06
CVE-2021-28207 ASUS BMC's firmware: path traversal - Get Help file function — BMC firmware for ASMB9-iKVM CWE-22 4.9 Medium 2021-04-06
CVE-2021-28205 ASUS BMC's firmware: path traversal - Delete SOL video file function — BMC firmware for Z10PR-D16 CWE-22 4.9 Medium 2021-04-06
CVE-2021-28206 ASUS BMC's firmware: path traversal - Record video file function — BMC firmware for ASMB9-iKVM CWE-22 4.9 Medium 2021-04-06
CVE-2021-28204 ASUS BMC's firmware: command injection - Modify user’s information function — BMC firmware for Z10PR-D16 CWE-78 7.2 High 2021-04-06
CVE-2021-28203 ASUS BMC's firmware: command injection - Web Set Media Image function — BMC firmware for Z10PR-D16 CWE-78 7.2 High 2021-04-06
CVE-2021-28202 ASUS BMC's firmware: buffer overflow - Service configuration-2 function — BMC firmware for ASMB9-iKVM CWE-120 4.9 Medium 2021-04-06
CVE-2021-28201 ASUS BMC's firmware: buffer overflow - Service configuration-1 function — BMC firmware for ASMB9-iKVM CWE-120 4.9 Medium 2021-04-06
CVE-2021-28199 ASUS BMC's firmware: buffer overflow - Modify user’s information function — BMC firmware for ASMB9-iKVM CWE-120 4.9 Medium 2021-04-06
CVE-2021-28200 ASUS BMC's firmware: buffer overflow - CD media configuration function — BMC firmware for ASMB9-iKVM CWE-120 4.9 Medium 2021-04-06
CVE-2021-28198 ASUS BMC's firmware: buffer overflow - Firmware protocol configuration — BMC firmware for ASMB9-iKVM CWE-120 4.9 Medium 2021-04-06
CVE-2021-28197 ASUS BMC's firmware: buffer overflow - Active Directory configuration function — BMC firmware for ASMB9-iKVM CWE-120 4.9 Medium 2021-04-06
CVE-2021-28196 ASUS BMC's firmware: buffer overflow - Generate SSL certificate function — BMC firmware for ASMB9-iKVM CWE-120 4.9 Medium 2021-04-06
CVE-2021-28194 ASUS BMC's firmware: buffer overflow - Remote image configuration setting — BMC firmware for ASMB9-iKVM CWE-120 4.9 Medium 2021-04-06

This page lists every published CVE security advisory associated with ASUS. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.