ASUS Known Exploited Vulnerabilities

Evidence-backed KEV intelligence for ASUS products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.

Total KEVs

6

In CISA KEV

3

Beyond CISA KEV

3

Sensor Observed

0

Virtual Patch Available

0

ASUS KEVs Added by Year

Loading...

6 ASUS KEVs added all time (primary attestation date).

Attested CVEs

CVE Confidence CISA KEV Added
CVE-2018-11511

The tree list functionality in the photo gallery application in ASUSTOR ADM 3.1.0.RFQ3 has a SQL injection vulnerability that affects the...

High Not in CISA 08 Dec 2025
CVE-2025-59374

"UNSUPPORTED WHEN ASSIGNED" Certain versions of the ASUS Live Update client were distributed with unauthorized modifications introduced...

Confirmed In CISA 01 Jun 2026
CVE-2023-39780

On ASUS RT-AX55 3.0.0.4.386.51598 devices, authenticated attackers can perform OS command injection via the /start_apply.htm qos_bw_rulelist...

Confirmed In CISA 01 Jun 2026
CVE-2021-32030

The administrator application on ASUS GT-AC2900 devices before 3.0.0.4.386.42643 and Lyra Mini before 3.0.0.4_384_46630 allows authentication...

Confirmed In CISA 28 Apr 2025
CVE-2018-20334

An issue was discovered in ASUSWRT 3.0.0.4.384.20308. When processing the /start_apply.htm POST data, there is a command injection issue via shell...

High Not in CISA 20 Mar 2020
CVE-2013-5948

The Network Analysis tab (Main_Analysis_Content.asp) in the ASUS RT-AC68U and other RT series routers with firmware before 3.0.0.4.374.5047 allows...

High Not in CISA 21 Apr 2014

Common Vulnerability Classes (CWE)

  • CWE-78 — Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') 3
  • CWE-287 — Improper Authentication 1
  • CWE-506 — Embedded Malicious Code 1
  • CWE-89 — Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') 1

Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology