Skip to content
COOEY

FAIL › dossier

asus

VENDOR

· dossier confidence 40%

ASUS, a major electronics manufacturer, has faced repeated critical security incidents, including supply chain compromises and remote code execution vulnerabilities in their router products, demonstrating a need for improved security practices and processes.

PROFILE
CategoryElectronics ManufacturingWhat they doASUS is a multinational company known for motherboards, PCs, monitors, graphics cards, and routers. They also offer gaming, content-creation, and AIoT solutions.OwnershipPublic Websitehttps://www.asus.com/ ↗
SECURITY POSTURE

ASUS has a history of critical security vulnerabilities in their router products, with evidence of active exploitation in the wild. Their security posture has been challenged by multiple remote code execution (RCE) vulnerabilities and buffer overflows.

Notable failures
  • Malicious code embedded in ASUS Live Update (CVE-2025-59374)
  • ASUS RT-AX55 routers OS command injection (CVE-2023-39780)
  • Improper authentication exposing routers to unauthorized access (CVE-2021-32030)
  • Buffer overflow in blocking_request.cgi (CVE-2021-45756)
  • CAPTCHA protection bypass (CVE-2021-41435)
  • Critical router flaw allowing command execution in MITM attacks (CVE-2026-13385)
Patterns: Recurring RCE vulnerabilities in router firmware; Supply chain compromise leading to malicious code injection; Vulnerabilities related to authentication and authorization
Reputationsevere-fallout (-0.11) · 7 trusted sources CoverageSentinelOne · app.opencve.io · cooey · cvefeed.io · www.cvefind.com · www.idtheftcenter.org
FAILURE HISTORY · 5
DATEEVENTSEVSUMMARY
2025-12-17 CVE-2025-59374 high ASUS Live Update had malicious code embedded, exploited in the wild
2025-06-02 CVE-2023-39780 high ASUS RT-AX55 routers OS command injection exploited remotely
2025-06-02 CVE-2021-32030 high ASUS routers with improper authentication exposed to unauthorized access
2022-03-23 CVE-2021-45756 critical Asus RT-AC68U <3.0.0.4.385.20633 and RT-AC5300 <3.0.0.4.384.82072 are affected by a buffer overflow in blocking_request.cgi.
2021-11-19 CVE-2021-41435 critical A brute-force protection bypass in CAPTCHA protection in ASUS ROG Rapture GT-AX11000, RT-AX3000, RT-AX55, RT-AX56U, RT-AX56U_V2, RT-AX58U, RT-AX82U, RT-AX82U GUNDAM EDITION, RT-AX86 Series(RT-AX86U/RT-AX86S), RT-AX86U ZAKU II EDITION, RT-AX88U, RT-AX92U, TUF Gaming AX3000, TUF Ga
SENTIMENT · TRUSTED SOURCES
synthesissevere-fallout-0.80
CVE-2021-41435 represents a critical brute-force bypass in ASUS router firmware affecting multiple high-profile products, allowing remote attackers to bypass CAPTCHA protection. While the vulnerabilit
cooey ↗severe-fallout-0.50
CVE disclosure
"A brute-force protection bypass in CAPTCHA protection in ASUS ROG Rapture GT-AX11000, RT-AX3000, RT-AX55, RT-AX56U, RT-AX56U_V2, RT-AX58U, RT-AX82U, RT-AX82U GUNDAM EDITION, RT-AX86 Series(RT-AX86U/RT-AX86S), RT-AX86U ZAKU II EDITION, RT-AX88U, RT-AX92U, TUF Gaming AX3000, TUF Gaming AX5400 (TUF-AX5400), ASUS ZenWiFi XD6, ASUS ZenWiFi AX (XT8) before 3.0.0.4.386.45898, and RT-AX68U before 3.0.0.4."
app.opencve.io ↗severe-fallout+0.00
neutral
www.cvefind.com ↗severe-fallout+0.00
neutral
SentinelOne ↗severe-fallout+0.00
neutral
www.wyff4.com ↗severe-fallout+0.00
neutral
cvefeed.io ↗severe-fallout-0.30
KEV inclusion
"CISA's Known Exploited Vulnerabilities (KEV) catalog is the authoritative list of security flaws that have been confirmed exploited in real-world attacks."
www.idtheftcenter.org ↗severe-fallout+0.00
neutral
Open questions: What specific measures are being taken to secure the ASUS Live Update process? · What is the extent of the impact from the ASUS Live Update compromise (CVE-2025-59374)? · What is ASUS's process for vulnerability disclosure and remediation?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-28 12:44:09.530140+00:00