Home
HIGH: 7.2 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HDefault status
unaffected
3.0.0.4_382 series (custom)
affected
3.0.0.4_386 series (custom)
affected
3.0.0.4_388 series (custom)
affected
3.0.0.6_102 series (custom)
affected
Description
An unintended entry point vulnerability has been identified in certain router models, which may allow for arbitrary command execution. Refer to the ' 01/02/2025 ASUS Router AiCloud vulnerability' section on the ASUS Security Advisory for more information.
Problem types
CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')
Product status
3.0.0.4_382 series (custom)
3.0.0.4_386 series (custom)
3.0.0.4_388 series (custom)
3.0.0.6_102 series (custom)
References
www.asus.com/content/asus-product-security-advisory/