ASUS Vulnerabilities and Affected Products
Explore source-attributed vulnerabilities associated with ASUS products.
Products
- BMC firmware for ASMB8-iKVM18 vulnerabilities
- BMC firmware for Z10PE-D16 WS18 vulnerabilities
- BMC firmware for Z10PR-D1618 vulnerabilities
- BMC firmware for ASMB9-iKVM17 vulnerabilities
- BMC firmware for E700 G417 vulnerabilities
- BMC firmware for ESC4000 DHD G417 vulnerabilities
- BMC firmware for ESC4000 G417 vulnerabilities
- BMC firmware for ESC4000 G4X17 vulnerabilities
- BMC firmware for ESC8000 G417 vulnerabilities
- BMC firmware for ESC8000 G4/10G17 vulnerabilities
- BMC firmware for KNPA-U1617 vulnerabilities
- BMC firmware for Pro E800 G417 vulnerabilities
- BMC firmware for RS100-E10-PI217 vulnerabilities
- BMC firmware for RS300-E10-PS417 vulnerabilities
- BMC firmware for RS300-E10-RS417 vulnerabilities
- BMC firmware for RS500-E9-PS417 vulnerabilities
- BMC firmware for RS500-E9-RS417 vulnerabilities
- BMC firmware for RS500-E9-RS4-U17 vulnerabilities
- BMC firmware for RS500A-E10-PS417 vulnerabilities
- BMC firmware for RS500A-E10-RS417 vulnerabilities
- BMC firmware for RS500A-E9 RS417 vulnerabilities
- BMC firmware for RS500A-E9-PS417 vulnerabilities
- BMC firmware for RS500A-E9-RS417 vulnerabilities
- BMC firmware for RS520-E9-RS12-E17 vulnerabilities
- BMC firmware for RS520-E9-RS817 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-8917HIGH | Generated title:ASUS GPU Tweak III, GPUTweakII, AI Suite3, and VGAdll Untrusted Pointer Dereference Privilege EscalationUntrusted Pointer Dereference in ASUS GPU Tweak III, GPUTweakII, AI Suite3, and VGAdll: An IOCTL vulnerability allows a local attacker to write a specific value to an arbitrary memory address, potentially leading to privilege escalation. Refer to the ' Security Update for ASUS GPU Tweak III, GPU Tweak II, AI Suite 3, and Armoury Crate Security Bulletin ' section on the ASUS Security Advisory for more information. CWE-822Aug 11, 2026 | CVSS8.4v4.0 | EPSS0.114% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-16727HIGH | Generated title:ASUS Armoury Crate Race Condition Leading to Local Privilege EscalationConcurrent Execution using Shared Resource with Improper Synchronization (“Race Condition”) in ASUS Armoury Crate allows a local user to execute arbitrary code with elevated privileges via a crafted file replacement. Refer to the ' Security Update for ASUS Armoury Crate ' section on the ASUS Security Advisory for more information. CWE-362Jul 30, 2026 | CVSS7.3v4.0 | EPSS0.087% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2019-25764HIGH | Generated title:ASUS AURA SYNC Exposed IOCTL with Insufficient Access Control**UNSUPPORTED WHEN ASSIGNED** Exposed IOCTL with Insufficient Access Control in the ASUS AURA SYNC driver allows a local user to bypass the driver's verification and invoke arbitrary IOCTLs, resulting in privilege escalation. Refer to the 'End-of-Life Notice and Driver Update for Legacy ASUS Drivers ' section on the ASUS Security Advisory for more information. CWE-782Jul 17, 2026 | CVSS7.3v4.0 | EPSS0.09% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-13385CRITICAL | Generated title:ASUS Router Improper Certificate Validation and Integrity Check Leading to Remote Code ExecutionAn Improper Validation of Integrity Check Value and Improper Certificate Validation in certain ASUS router models allows a remote man-in-the-middle(MITM) user to make the router download and execute arbitrary command via a spoofed server. Refer to the ' Security Update for ASUS Router Firmware ' section on the ASUS Security Advisory for more information. | CVSS9.5v4.0 | EPSS0.142% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-15029HIGH | Generated title:ASUS System Control Interface v3, System Control Interface, and Business Manager Untrusted Pointer DereferenceUntrusted Pointer Dereference in ASUS System Control Interface v3, ASUS System Control Interface, and ASUS Business Manager allows a local administrator to perform arbitrary physical memory read and write operations via crafted IOCTL requests to the driver, bypassing OS-enforced memory protections. Refer to the ' Security Update for ASUS System Control Interface ' section on the ASUS Security Advisory for more information. CWE-822Jul 15, 2026 | CVSS8.4v4.0 | EPSS0.135% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-15030MEDIUM | Generated title:ASUS System Control Interface v3, System Control Interface, and Business Manager Out-of-bounds ReadOut-of-bounds Read in ASUS System Control Interface v3, ASUS System Control Interface, and ASUS Business Manager allows a local administrator to read memory regions beyond the intended firmware boundary by supplying a crafted IOCTL request that bypasses the validation. Refer to the ' Security Update for ASUS System Control Interface ' section on the ASUS Security Advisory for more information. CWE-125Jul 15, 2026 | CVSS5.6v4.0 | EPSS0.112% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-13585HIGH | Generated title:ASUS bsitf.sys Kernel Driver IOCTL 0x222808 Kernel Memory Mapping to UsermodeAllocation of Resources Without Limits and Throttling and Sensitive Information in Resource Not Removed Before Reuse in the ASUS System Control Interface driver and ASUS Business Manager allow a local administrator to disclose sensitive information via crafted IOCTL requests, which, in severe cases, may lead to a Denial of Service (DoS) on the system. Refer to the ' Security Update for ASUS System Control Interface ' section on the ASUS Security Advisory for more information. | CVSS8.2v4.0 | EPSS0.307% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-8920HIGH | Generated title:ASUS Aura Wallpaper Service Arbitrary File Operations via Path TraversalImproper Restriction of Communication Channel to Intended Endpoints and External Control of File Name or Path in Aura Wallpaper Service allow a local user to perform file operations by sending crafted commands containing an arbitrary file path and bypassing the service’s path restrictions . On specific models , this can also cause a single feature to become unavailable . Refer to the ' Security Update for Aura Wallpaper Service ' section on the ASUS Security Advisory for more information. | CVSS8.5v4.0 | EPSS0.1% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-8919HIGH | Generated title:ASUS GameSDK Permissive Cross-domain Security Policy with Untrusted DomainsPermissive Cross-domain Security Policy with Untrusted Domains in ASUS GameSDK allows a remote user to obtain a local user’s NTLM hash by convincing the user to visit a crafted web page that sends a request containing a UNC path to the application’s local service endpoint. This can result in information disclosure or data tampering, may cause GameSDK to become unavailable, and may also enable access to the victim’s information on other services. Refer to the ' Security Update for ASUS GameSDK '… CWE-942Jul 15, 2026 | CVSS7.2v4.0 | EPSS0.3% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-11851MEDIUM | Generated title:ASUS Router Web Management Interface SQL InjectionImproper Neutralization of Special Elements used in an SQL Command ("SQL Injection") in the web management interface of certain ASUS router models allows a remote authenticated user to disclose confidential information via a crafted request that bypasses existing input validation Refer to the ' Security Update for ASUS Router Firmware ' section on the ASUS Security Advisory for more information. CWE-89Jul 15, 2026 | CVSS5.9v4.0 | EPSS0.368% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-4989HIGH | Generated title:ASUS AI Suite 3 Driver Improper Input Validation Leading to Privilege Escalation** UNSUPPORTED WHEN ASSIGNED ** Improper Validation of Specified Quantity in Input in the ASUS AI Suite 3 driver allows a local user to access unintended memory regions via crafted IOCTL requests, leading to privilege escalation. Refer to the 'End-of-Life Notice and Driver Update for Legacy ASUS Drivers ' section on the ASUS Security Advisory for more information. CWE-1284Jul 3, 2026 | CVSS8.5v4.0 | EPSS0.103% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-4990HIGH | Generated title:ASUS AI Suite 3 Driver Improper Input Validation Leading to Privilege Escalation** UNSUPPORTED WHEN ASSIGNED ** Improper Validation of Specified Quantity in Input in the ASUS AI Suite 3 driver allows a local user to bypass security validation and access restricted memory blocks via crafted IOCTL requests, leading to privilege escalation. Refer to the 'End-of-Life Notice and Driver Update for Legacy ASUS Drivers ' section on the ASUS Security Advisory for more information. CWE-1284Jul 3, 2026 | CVSS7.3v4.0 | EPSS0.096% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-8921HIGH | Generated title:ASUS Business Manager External Control of File Name or Path Leading to Local Privilege EscalationExternal Control of File Name or Path vulnerability in ASUS Business Manager allows a local user to execute arbitrary code with SYSTEM privileges via a tampered IPC message. Refer to the ' Security Update for ASUS Business Manager ' section on the ASUS Security Advisory for more information. CWE-73Jul 3, 2026 | CVSS8.5v4.0 | EPSS0.124% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-12960MEDIUM | Generated title:ASUS Router App Improper Export of Android Application ComponentsAn Improper Export of Android Application Components vulnerability in ASUS Router App allows a third-party application on the same device to send a crafted Intent that causes ASUS Router App to open an specified URL. Refer to the ' Security Update for ASUS Router Android App ' section on the ASUS Security Advisory for more information. CWE-926Jul 3, 2026 | CVSS6.0v4.0 | EPSS0.119% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-8918HIGH | Generated title:ASUS Armoury Crate Permissive List of Inputs Local Arbitrary Memory Read/WriteA permissive list of allowed inputs in ASUS Armoury Crate allows a local administrator to perform arbitrary memory read/write operations or cause a system crash (BSOD) by bypassing the validation mechanism.Refer to the ' Security Update for Armoury Crate App ' section on the ASUS Security Advisory for more information. CWE-183Jun 22, 2026 | CVSS7.1v4.0 | EPSS0.279% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-7480HIGH | Generated title:ASUS System Control Interface Incorrect Permission Assignment Local Privilege EscalationAn Incorrect Permission Assignment for Critical Resource vulnerability in ASUS System Control Interface allows a local user to elevate privileges to SYSTEM and execute arbitrary code via a crafted RPC call that bypass the validation mechanism. Refer to the 'Security Update for ASUS System Control Interface' section on the ASUS Security Advisory for more information. CWE-732May 29, 2026 | CVSS7.3v4.0 | EPSS0.135% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-8070HIGH | Generated title:ASUS Armoury Crate Incorrect Permission Assignment for Critical ResourceIncorrect permission assignment for a critical resource in Armoury Crate allows a local user to bypass the driver’s validation mechanism, resulting in unauthorized read and write access to physical memory.Refer to the ' Security Update for Armoury Crate App ' section on the ASUS Security Advisory for more information. CWE-732May 29, 2026 | CVSS7.3v4.0 | EPSS0.09% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-3508MEDIUM | Generated title:Out-of-Bounds Read in ASUS System Control Interface IOCTL HandlerAn Out-of-bounds Read vulnerability in the IOCTL handler in ASUS System Control Interface allows a local user to cause system crash (BSOD) via a read size that exceeds the buffer size.Refer to the ' Security Update for MyASUS ' section on the ASUS Security Advisory for more information. CWE-125May 8, 2026 | CVSS6.8v4.0 | EPSS0.137% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
Generated title:ASUS AsusPTPFilter Exposed IOCTL with Insufficient Access ControlAn Exposed IOCTL with Insufficient Access Control vulnerability in AsusPTPFilter allows a local user to bypass driver security mechanisms and obtain restricted touchpad information or render the touchpad unusable via crafted IOCTL requests.Refer to the ' Security Update for ASUS Precision Touchpad ' section on the ASUS Security Advisory for more information. CWE-782May 8, 2026 | CVSS2.0v4.0 | EPSS0.092% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2026-3428MEDIUM | Generated title:ASUS Member Center TOCTOU Race Condition Leading to Privilege EscalationA Download of Code Without Integrity Check vulnerability in the update modules in ASUS Member Center(华硕大厅) allows a local user to achieve privilege escalation to Administrator via exploitation of a Time-of-check Time-of-use (TOC-TOU) during the update process, where an unexpected payload is substituted for a legitimate one immediately after download, and subsequently executed with administrative privileges upon user consent. Refer to the 'Security Update for ASUS Member Center' section on the AS… | CVSS5.4v4.0 | EPSS0.074% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-1880MEDIUM | Generated title:ASUS DriverHub TOCTOU Privilege EscalationAn Incorrect Permission Assignment for Critical Resource vulnerability in the ASUS DriverHub update process allows privilege escalation due to improper protection of required execution resources during the validation phase, permitting a local user to make unprivileged modifications. This allows the altered resource to pass system checks and be executed with elevated privileges upon a user-initiated update. Refer to the 'Security Update for ASUS DriverHub' section on the ASUS Security Advisory fo… CWE-367Apr 16, 2026 | CVSS5.4v4.0 | EPSS0.139% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-15101HIGH | Generated title:ASUS Router Web Management Interface OS Command InjectionAn OS command injection vulnerability in the web management interface of certain ASUS router models allows remote authenticated administrators to execute arbitrary system commands via a crafted parameter. Refer to the 'Security Update for ASUS Router Firmware' section on the ASUS Security Advisory for more information. CWE-78Mar 26, 2026 | CVSS8.6v4.0 | EPSS0.899% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-15038MEDIUM | Generated title:ASUS Business System Control Interface Driver Out-of-Bounds ReadAn Out-of-Bounds Read vulnerability exists in the ASUS Business System Control Interface driver. This vulnerability can be triggered by an unprivileged local user sending a specially crafted IOCTL request, potentially leading to a disclosure of kernel information or a system crash. Refer to the "Security Update for ASUS Business System Control Interface" section on the ASUS Security Advisory for more information. CWE-125Mar 12, 2026 | CVSS6.9v4.0 | EPSS0.108% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-1878MEDIUM | Generated title:ASUS ROG Peripheral Driver Installation Insufficient Integrity Verification Privilege EscalationAn Insufficient Integrity Verification vulnerability in the ASUS ROG peripheral driver installation process allows privilege escalation to SYSTEM. The vulnerability is due to improper access control on the installation directory, which enables the exploitation of a race condition where the legitimate installer is substituted with an unexpected payload immediately after download, resulting in arbitrary code execution. Refer to the "Security Update for ASUS ROG peripheral driver" section on the AS… CWE-494Mar 12, 2026 | CVSS5.4v4.0 | EPSS0.13% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-15037MEDIUM | Generated title:ASUS Business System Control Interface Incorrect Permission Assignment Leading to Information DisclosureAn Incorrect Permission Assignment vulnerability exists in the ASUS Business System Control Interface driver. This vulnerability can be triggered by an unprivileged local user sending a specially crafted IOCTL request, potentially leading to unauthorized access to sensitive hardware resources and kernel information disclosure. Refer to the "ASUS Business System Control Interface" section on the ASUS Security Advisory for more information. CWE-732Mar 12, 2026 | CVSS6.8v4.0 | EPSS0.099% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |