ASUSTeK Computer Incorporation

First CVE: Dec 4, 2024Active for: 2 years
57
CVEs Published
More CVEs Published than 61% of tracked CNAs
19.0
Avg CVEs / Year
More Avg CVEs / Year than 67% of tracked CNAs
7.2
Avg CVSS Score
Higher Avg CVSS Score than 55% of tracked CNAs
1.8%
In CISA KEV
Higher KEV Rate than 91% of tracked CNAs

Self-Reporting Analysis

Of all the CVEs published by ASUSTeK Computer Incorporation as a CNA, 14.0% affect products that ASUSTeK Computer Incorporation develops as a vendor.

14.0%
86.0%
Self-reported: 8Third-party: 49

Of all the CVEs published that affect products developed by ASUSTeK Computer Incorporation, 2.9% are self-published by ASUSTeK Computer Incorporation as a CNA.

97.1%
Self-published: 8Published by other CNAs: 270

Trends Over Time

The number and severity of CVEs published by ASUSTeK Computer Incorporation over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 4, 2024
19 months ago
Most Recent CVE
Jul 17, 2026
7 days ago

Top CVEs

All CVEs published by ASUSTeK Computer Incorporation as a CNA, regardless of affected vendor or product.

57 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
"UNSUPPORTED WHEN ASSIGNED" Certain versions of the ASUS Live Update client were distributed with unauthorized modifications introduced through a supply chain compromise. The modif
Dec 17, 20259.875YESNO
An Improper Validation of Integrity Check Value and Improper Certificate Validation in certain ASUS router models allows a remote man-in-the-middle(MITM) user to make the router do
Jul 15, 20269.543NONO
An authentication-bypass vulnerability exists in AiCloud. This vulnerability can be triggered by an unintended side effect of the Samba functionality, potentially leading to allow
Nov 25, 20259.242NONO
Allocation of Resources Without Limits and Throttling and Sensitive Information in Resource Not Removed Before Reuse in the ASUS System Control Interface driver and ASUS Business M
Jul 15, 20268.241NONO
Improper Restriction of Communication Channel to Intended Endpoints and External Control of File Name or Path in Aura Wallpaper Service allow a local user to perform file operation
Jul 15, 20268.537NONO
External Control of File Name or Path vulnerability in ASUS Business Manager allows a local user to execute arbitrary code with SYSTEM privileges via a tampered IPC message. Refer
Jul 3, 20268.537NONO
Untrusted Pointer Dereference in ASUS System Control Interface v3, ASUS System Control Interface, and ASUS Business Manager allows a local administrator to perform arbitrary physic
Jul 15, 20268.436NONO
** UNSUPPORTED WHEN ASSIGNED ** Improper Validation of Specified Quantity in Input in the ASUS AI Suite 3 driver allows a local user to access unintended memory regions via crafted
Jul 3, 20268.535NONO
An authentication bypass vulnerability has been identified in certain DSL series routers, may allow remote attackers to gain unauthorized access into the affected system. Refer to
Nov 13, 20259.835NONO
Permissive Cross-domain Security Policy with Untrusted Domains in ASUS GameSDK allows a remote user to obtain a local user’s NTLM hash by convincing the user to visit a crafted web
Jul 15, 20267.233NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA57 CVEs
Severity distribution among all CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local32 (56.1%)
Network24 (42.1%)
Unknown0 (0.0%)
Physical1 (1.8%)
Adjacent Network0 (0.0%)
Attack Complexity
Low45 (78.9%)
High12 (21.1%)
Unknown0 (0.0%)
User Interaction
None47 (82.5%)
Unknown0 (0.0%)
Required2 (3.5%)
Privileges Required
Low24 (42.1%)
High15 (26.3%)
None18 (31.6%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (57 CVEs).

CISA KEV
1 CVE
1.8% of CVEs· 91st percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by ASUSTeK Computer Incorporation as a CNA.

Media Mentions

Media articles that mention a CVE ID published by ASUSTeK Computer Incorporation as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs