ASUS Known Exploited Vulnerabilities
Evidence-backed KEV intelligence for ASUS products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.
Total KEVs
6
In CISA KEV
3
Beyond CISA KEV
3
Sensor Observed
0
Virtual Patch Available
0
ASUS KEVs Added by Year
6 ASUS KEVs added all time (primary attestation date).
Attested CVEs
| CVE | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2018-11511
The tree list functionality in the photo gallery application in ASUSTOR ADM 3.1.0.RFQ3 has a SQL injection vulnerability that affects the... |
ADM | High | Not in CISA | 08 Dec 2025 |
|
CVE-2025-59374
"UNSUPPORTED WHEN ASSIGNED" Certain versions of the ASUS Live Update client were distributed with unauthorized modifications introduced... |
live update | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2023-39780
On ASUS RT-AX55 3.0.0.4.386.51598 devices, authenticated attackers can perform OS command injection via the /start_apply.htm qos_bw_rulelist... |
RT-AX55 | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2021-32030
The administrator application on ASUS GT-AC2900 devices before 3.0.0.4.386.42643 and Lyra Mini before 3.0.0.4_384_46630 allows authentication... |
GT-AC2900, Lyra Mini | Confirmed | In CISA | 28 Apr 2025 |
|
CVE-2018-20334
An issue was discovered in ASUSWRT 3.0.0.4.384.20308. When processing the /start_apply.htm POST data, there is a command injection issue via shell... |
ASUSWRT | High | Not in CISA | 20 Mar 2020 |
|
CVE-2013-5948
The Network Analysis tab (Main_Analysis_Content.asp) in the ASUS RT-AC68U and other RT series routers with firmware before 3.0.0.4.374.5047 allows... |
RT-AC68U | High | Not in CISA | 21 Apr 2014 |
Common Vulnerability Classes (CWE)
- CWE-78 — Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') 3
- CWE-287 — Improper Authentication 1
- CWE-506 — Embedded Malicious Code 1
- CWE-89 — Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') 1
Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology