Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

ASUSTeK Computer Incorporation

First CVE: Nov 4, 2005Active for: 21 yearsTotal CVEs: 278
56.3
VTI Score
TOP TARGET

ASUSTeK Computer Incorporation maintains a broad portfolio of consumer and small-business networking devices—routers, embedded management appliances, and related network infrastructure—that ranks among the most prevalent device categories in the global vulnerability landscape. Vulnerabilities affecting the vendor skew toward serious outcomes, with a meaningful share reaching critical severity and a moderate tendency toward public exploit availability, reflecting the appeal of internet-connected networking hardware for reconnaissance and lateral movement. The exposure recurs across product lines such as the RT-AC86U and RT-AC68U router families and embedded management firmware, driven by weakness classes including buffer overflows, cross-site scripting, OS command injection, and improper memory-buffer bounds checking—vulnerabilities endemic to firmware with limited memory safety enforcement and web-based management interfaces. Defenders should prioritize inventory and access restriction for these devices, particularly those exposed to untrusted networks, and track the vendor's advisory releases systematically given the scale of affected deployments. Live severity, exploitation, and current exposure counts are shown alongside this summary.

FAUCET AI Generated
278
Total CVEs
More Total CVEs than 100% of tracked vendors
0.0
Avg CVEs / Product / Year
Bottom 1%
7.3
Avg CVSS Score
Higher Avg CVSS Score than 55% of tracked vendors
1.1%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by ASUSTeK Computer Incorporation over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 4, 2005
20 years ago
Most Recent CVE
Jul 17, 2026
7 days ago

Self-Reporting Analysis

Of all the CVEs published by ASUSTeK Computer Incorporation as a CNA, 14.0% affect products that ASUSTeK Computer Incorporation develops as a vendor.

14.0%
86.0%
Self-reported: 8 (14.0%)
Third-party: 49 (86.0%)

Of all the CVEs published that affect products developed by ASUSTeK Computer Incorporation, 2.9% are self-published by ASUSTeK Computer Incorporation as a CNA.

97.1%
Self-published: 8 (2.9%)
Other CNAs: 270 (97.1%)

Products(901 total)

Top CVEs

Signals from CVEs in this vendor scope (278 CVEs).

278 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-32030CRITICAL
The administrator application on ASUS GT-AC2900 devices before 3.0.0.4.386.42643 and Lyra Mini before 3.0.0.4_384_46630 allows authentication bypass when processing remote input fr
May 6, 20219.898YESYES
CVE-2018-6000CRITICAL
An issue was discovered in AsusWRT before 3.0.0.4.384_10007. The do_vpnupload_post function in router/httpd/web.c in vpnupload.cgi provides functionality for setting NVRAM configur
Jan 22, 20189.889NOYES
CVE-2018-5999CRITICAL
An issue was discovered in AsusWRT before 3.0.0.4.384_10007. In the handle_request function in router/httpd/httpd.c, processing of POST requests continues even if authentication fa
Jan 22, 20189.889NOYES
CVE-2014-9583HIGH
common.c in infosvr in ASUS WRT firmware 3.0.0.4.376_1071, 3.0.0.376.2524-g0013f52, and other versions, as used in RT-AC66U, RT-N66U, and other routers, does not properly check the
Jan 8, 201510.086NOYES
CVE-2023-39780HIGH
On ASUS RT-AX55 3.0.0.4.386.51598 devices, authenticated attackers can perform OS command injection via the /start_apply.htm qos_bw_rulelist parameter. NOTE: for the similar "token
Sep 11, 20238.882YESNO
CVE-2008-1491HIGH
Stack-based buffer overflow in the DPC Proxy server (DpcProxy.exe) in ASUS Remote Console (aka ARC or ASMB3) 2.0.0.19 and 2.0.0.24 allows remote attackers to execute arbitrary code
Mar 25, 200810.082NOYES
CVE-2025-59374CRITICAL
"UNSUPPORTED WHEN ASSIGNED" Certain versions of the ASUS Live Update client were distributed with unauthorized modifications introduced through a supply chain compromise. The modif
Dec 17, 20259.875YESNO
CVE-2012-4924HIGH
Buffer overflow in the CxDbgPrint function in the ipswcom.dll ActiveX component 1.0.0.1 for ASUS Net4Switch 1.0.0020 allows remote attackers to execute arbitrary code via a long pa
Sep 15, 20129.365NOYES
CVE-2017-6548CRITICAL
Buffer overflows in networkmap on ASUS RT-N56U, RT-N66U, RT-AC66U, RT-N66R, RT-AC66R, RT-AC68U, RT-AC68R, RT-N66W, RT-AC66W, RT-AC87R, RT-AC87U, RT-AC51U, RT-AC68P, RT-N11P, RT-N12
Mar 9, 20179.853NOYES
CVE-2023-26602CRITICAL
ASUS ASMB8 iKVM firmware through 1.14.51 allows remote attackers to execute arbitrary code by using SNMP to create extensions, as demonstrated by snmpset for NET-SNMP-EXTEND-MIB wi
Feb 26, 20239.851NOYES
View all 278 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products278 CVEs
35%
50%
14%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local57 (20.5%)
Network178 (64.0%)
Unknown24 (8.6%)
Physical3 (1.1%)
Adjacent Network16 (5.8%)
Attack Complexity
Low243 (87.4%)
High11 (4.0%)
Unknown24 (8.6%)
User Interaction
None214 (77.0%)
Unknown24 (8.6%)
Required40 (14.4%)
Privileges Required
Low82 (29.5%)
High48 (17.3%)
None124 (44.6%)
Unknown24 (8.6%)

Exploit Exposure

Signals from CVEs in this vendor scope (278 CVEs).

CISA KEV
3 CVEs
1.1% of CVEs· 99th percentile
Metasploit
5 CVEs
1.8% of CVEs· 97th percentile
Nuclei
1 CVE
0.4% of CVEs· 95th percentile
ExploitDB
16 CVEs
5.8% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by ASUSTeK Computer Incorporation.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by ASUSTeK Computer Incorporation — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For ASUSTeK Computer Incorporation's Products

View all 9 CNAs →

Top CWEs