CVE-2025-2492

CRITICAL EXPLOITED

AiCloud - Auth Bypass

Title source: llm
STIX 2.1

Description

An improper authentication control vulnerability exists in AiCloud. This vulnerability can be triggered by a crafted request, potentially leading to unauthorized execution of functions. Refer to the 'ASUS Router AiCloud vulnerability' section on the ASUS Security Advisory for more information.

Scores

CVSS v4 9.2
EPSS 0.0046
EPSS Percentile 63.9%
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

VulnCheck KEV 2025-11-19
CWE
CWE-288
Status published
Products (4)
ASUS/Router 3.0.0.4_382 series
ASUS/Router 3.0.0.4_386 series
ASUS/Router 3.0.0.4_388 series
ASUS/Router 3.0.0.6_102 series
Published Apr 18, 2025
Tracked Since Feb 18, 2026