ASUSTeK Computer Incorporation
Self-Reporting Analysis
Of all the CVEs published by ASUSTeK Computer Incorporation as a CNA, 14.0% affect products that ASUSTeK Computer Incorporation develops as a vendor.
Of all the CVEs published that affect products developed by ASUSTeK Computer Incorporation, 2.9% are self-published by ASUSTeK Computer Incorporation as a CNA.
Trends Over Time
The number and severity of CVEs published by ASUSTeK Computer Incorporation over time
Top CVEs
All CVEs published by ASUSTeK Computer Incorporation as a CNA, regardless of affected vendor or product.
57 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-59374CRITICAL "UNSUPPORTED WHEN ASSIGNED" Certain versions of the ASUS Live Update client were distributed with unauthorized modifications introduced through a supply chain compromise. The modif | Dec 17, 2025 | 9.8 | 75 | YES | NO |
CVE-2026-13385CRITICAL An Improper Validation of Integrity Check Value and Improper Certificate Validation in certain ASUS router models allows a remote man-in-the-middle(MITM) user to make the router do | Jul 15, 2026 | 9.5 | 43 | NO | NO |
CVE-2025-59366CRITICAL An authentication-bypass vulnerability exists in AiCloud. This vulnerability can be triggered by an unintended side effect of the Samba functionality, potentially leading to allow | Nov 25, 2025 | 9.2 | 42 | NO | NO |
CVE-2026-13585HIGH Allocation of Resources Without Limits and Throttling and Sensitive Information in Resource Not Removed Before Reuse in the ASUS System Control Interface driver and ASUS Business M | Jul 15, 2026 | 8.2 | 41 | NO | NO |
CVE-2026-8920HIGH Improper Restriction of Communication Channel to Intended Endpoints and External Control of File Name or Path in Aura Wallpaper Service allow a local user to perform file operation | Jul 15, 2026 | 8.5 | 37 | NO | NO |
CVE-2026-8921HIGH External Control of File Name or Path vulnerability in ASUS Business Manager allows a local user to execute arbitrary code with SYSTEM privileges via a tampered IPC message.
Refer | Jul 3, 2026 | 8.5 | 37 | NO | NO |
CVE-2026-15029HIGH Untrusted Pointer Dereference in ASUS System Control Interface v3, ASUS System Control Interface, and ASUS Business Manager allows a local administrator to perform arbitrary physic | Jul 15, 2026 | 8.4 | 36 | NO | NO |
CVE-2022-4989HIGH ** UNSUPPORTED WHEN ASSIGNED ** Improper Validation of Specified Quantity in Input in the ASUS AI Suite 3 driver allows a local user to access unintended memory regions via crafted | Jul 3, 2026 | 8.5 | 35 | NO | NO |
CVE-2025-59367CRITICAL An authentication bypass vulnerability has been identified in certain DSL series routers, may allow remote attackers to gain unauthorized access into the affected system. Refer to | Nov 13, 2025 | 9.8 | 35 | NO | NO |
CVE-2026-8919HIGH Permissive Cross-domain Security Policy with Untrusted Domains in ASUS GameSDK allows a remote user to obtain a local user’s NTLM hash by convincing the user to visit a crafted web | Jul 15, 2026 | 7.2 | 33 | NO | NO |
CVE Severity & Scoring
Exploit Exposure
Signals from CVEs in this cna scope (57 CVEs).
Social Chatter
An overview of all social media posts that mention a CVE ID published by ASUSTeK Computer Incorporation as a CNA.
Media Mentions
Media articles that mention a CVE ID published by ASUSTeK Computer Incorporation as a CNA — matched by CVE ID, not by organization name.