Description
An authentication bypass vulnerability has been identified in the IFTTT integration feature. A remote, authenticated attacker could leverage this vulnerability to potentially gain unauthorized access to the device. This vulnerability does not affect Wi-Fi 7 series models. Refer to the 'Security Update for ASUS Router Firmware' section on the ASUS Security Advisory for more information.
References (1)
Scores
CVSS v4
7.5
EPSS
0.0015
EPSS Percentile
35.1%
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-330
Status
published
Products (3)
ASUS/Router
3.0.0.4_386
ASUS/Router
3.0.0.4_388
ASUS/Router
3.0.0.6_102
Published
Nov 25, 2025
Tracked Since
Feb 18, 2026