CVE-2025-3464
HIGHArmoury Crate - Auth Bypass
Title source: llmDescription
A race condition vulnerability exists in Armoury Crate. This vulnerability arises from a Time-of-check Time-of-use issue, potentially leading to authentication bypass. Refer to the 'Security Update for Armoury Crate App' section on the ASUS Security Advisory for more information.
Exploits (1)
Scores
CVSS v4
8.4
EPSS
0.0008
EPSS Percentile
23.9%
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:H/SC:L/SI:H/SA:H
Details
CWE
CWE-367
Status
published
Products (1)
ASUS/Armoury Crate
v5.9.9.0~v6.1.18
Published
Jun 16, 2025
Tracked Since
Feb 18, 2026