ASUSTeK Computer Incorporation maintains a broad portfolio of consumer and small-business networking devices—routers, embedded management appliances, and related network infrastructure—that ranks among the most prevalent device categories in the global vulnerability landscape. Vulnerabilities affecting the vendor skew toward serious outcomes, with a meaningful share reaching critical severity and a moderate tendency toward public exploit availability, reflecting the appeal of internet-connected networking hardware for reconnaissance and lateral movement. The exposure recurs across product lines such as the RT-AC86U and RT-AC68U router families and embedded management firmware, driven by weakness classes including buffer overflows, cross-site scripting, OS command injection, and improper memory-buffer bounds checking—vulnerabilities endemic to firmware with limited memory safety enforcement and web-based management interfaces. Defenders should prioritize inventory and access restriction for these devices, particularly those exposed to untrusted networks, and track the vendor's advisory releases systematically given the scale of affected deployments. Live severity, exploitation, and current exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by ASUSTeK Computer Incorporation over time
Of all the CVEs published by ASUSTeK Computer Incorporation as a CNA, 14.0% affect products that ASUSTeK Computer Incorporation develops as a vendor.
Of all the CVEs published that affect products developed by ASUSTeK Computer Incorporation, 2.9% are self-published by ASUSTeK Computer Incorporation as a CNA.
Signals from CVEs in this vendor scope (278 CVEs).
278 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-32030CRITICAL The administrator application on ASUS GT-AC2900 devices before 3.0.0.4.386.42643 and Lyra Mini before 3.0.0.4_384_46630 allows authentication bypass when processing remote input fr | May 6, 2021 | 9.8 | 98 | YES | YES |
CVE-2018-6000CRITICAL An issue was discovered in AsusWRT before 3.0.0.4.384_10007. The do_vpnupload_post function in router/httpd/web.c in vpnupload.cgi provides functionality for setting NVRAM configur | Jan 22, 2018 | 9.8 | 89 | NO | YES |
CVE-2018-5999CRITICAL An issue was discovered in AsusWRT before 3.0.0.4.384_10007. In the handle_request function in router/httpd/httpd.c, processing of POST requests continues even if authentication fa | Jan 22, 2018 | 9.8 | 89 | NO | YES |
CVE-2014-9583HIGH common.c in infosvr in ASUS WRT firmware 3.0.0.4.376_1071, 3.0.0.376.2524-g0013f52, and other versions, as used in RT-AC66U, RT-N66U, and other routers, does not properly check the | Jan 8, 2015 | 10.0 | 86 | NO | YES |
CVE-2023-39780HIGH On ASUS RT-AX55 3.0.0.4.386.51598 devices, authenticated attackers can perform OS command injection via the /start_apply.htm qos_bw_rulelist parameter. NOTE: for the similar "token | Sep 11, 2023 | 8.8 | 82 | YES | NO |
CVE-2008-1491HIGH Stack-based buffer overflow in the DPC Proxy server (DpcProxy.exe) in ASUS Remote Console (aka ARC or ASMB3) 2.0.0.19 and 2.0.0.24 allows remote attackers to execute arbitrary code | Mar 25, 2008 | 10.0 | 82 | NO | YES |
CVE-2025-59374CRITICAL "UNSUPPORTED WHEN ASSIGNED" Certain versions of the ASUS Live Update client were distributed with unauthorized modifications introduced through a supply chain compromise. The modif | Dec 17, 2025 | 9.8 | 75 | YES | NO |
CVE-2012-4924HIGH Buffer overflow in the CxDbgPrint function in the ipswcom.dll ActiveX component 1.0.0.1 for ASUS Net4Switch 1.0.0020 allows remote attackers to execute arbitrary code via a long pa | Sep 15, 2012 | 9.3 | 65 | NO | YES |
CVE-2017-6548CRITICAL Buffer overflows in networkmap on ASUS RT-N56U, RT-N66U, RT-AC66U, RT-N66R, RT-AC66R, RT-AC68U, RT-AC68R, RT-N66W, RT-AC66W, RT-AC87R, RT-AC87U, RT-AC51U, RT-AC68P, RT-N11P, RT-N12 | Mar 9, 2017 | 9.8 | 53 | NO | YES |
CVE-2023-26602CRITICAL ASUS ASMB8 iKVM firmware through 1.14.51 allows remote attackers to execute arbitrary code by using SNMP to create extensions, as demonstrated by snmpset for NET-SNMP-EXTEND-MIB wi | Feb 26, 2023 | 9.8 | 51 | NO | YES |
Signals from CVEs in this vendor scope (278 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by ASUSTeK Computer Incorporation.
Media articles that mention a CVE ID that affects a product developed by ASUSTeK Computer Incorporation — matched by CVE ID, not by vendor name.