FAIL › dossier
asus
VENDOR· dossier confidence 40%
ASUS, a major electronics manufacturer, has faced repeated critical security incidents, including supply chain compromises and remote code execution vulnerabilities in their router products, demonstrating a need for improved security practices and processes.
PROFILE
CategoryElectronics ManufacturingWhat they doASUS is a multinational company known for motherboards, PCs, monitors, graphics cards, and routers. They also offer gaming, content-creation, and AIoT solutions.OwnershipPublic
Websitehttps://www.asus.com/ ↗
SECURITY POSTURE
ASUS has a history of critical security vulnerabilities in their router products, with evidence of active exploitation in the wild. Their security posture has been challenged by multiple remote code execution (RCE) vulnerabilities and buffer overflows.
Notable failures
- Malicious code embedded in ASUS Live Update (CVE-2025-59374)
- ASUS RT-AX55 routers OS command injection (CVE-2023-39780)
- Improper authentication exposing routers to unauthorized access (CVE-2021-32030)
- Buffer overflow in blocking_request.cgi (CVE-2021-45756)
- CAPTCHA protection bypass (CVE-2021-41435)
- Critical router flaw allowing command execution in MITM attacks (CVE-2026-13385)
Patterns: Recurring RCE vulnerabilities in router firmware; Supply chain compromise leading to malicious code injection; Vulnerabilities related to authentication and authorization
Reputationsevere-fallout (-0.11) · 7 trusted sources
CoverageSentinelOne · app.opencve.io · cooey · cvefeed.io · www.cvefind.com · www.idtheftcenter.org
FAILURE HISTORY · 5
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2025-12-17 | CVE-2025-59374 | high | ASUS Live Update had malicious code embedded, exploited in the wild |
| 2025-06-02 | CVE-2023-39780 | high | ASUS RT-AX55 routers OS command injection exploited remotely |
| 2025-06-02 | CVE-2021-32030 | high | ASUS routers with improper authentication exposed to unauthorized access |
| 2022-03-23 | CVE-2021-45756 | critical | Asus RT-AC68U <3.0.0.4.385.20633 and RT-AC5300 <3.0.0.4.384.82072 are affected by a buffer overflow in blocking_request.cgi. |
| 2021-11-19 | CVE-2021-41435 | critical | A brute-force protection bypass in CAPTCHA protection in ASUS ROG Rapture GT-AX11000, RT-AX3000, RT-AX55, RT-AX56U, RT-AX56U_V2, RT-AX58U, RT-AX82U, RT-AX82U GUNDAM EDITION, RT-AX86 Series(RT-AX86U/RT-AX86S), RT-AX86U ZAKU II EDITION, RT-AX88U, RT-AX92U, TUF Gaming AX3000, TUF Ga |
SENTIMENT · TRUSTED SOURCES
synthesissevere-fallout-0.80
CVE-2021-41435 represents a critical brute-force bypass in ASUS router firmware affecting multiple high-profile products, allowing remote attackers to bypass CAPTCHA protection. While the vulnerabilit
CVE disclosure
"A brute-force protection bypass in CAPTCHA protection in ASUS ROG Rapture GT-AX11000, RT-AX3000, RT-AX55, RT-AX56U, RT-AX56U_V2, RT-AX58U, RT-AX82U, RT-AX82U GUNDAM EDITION, RT-AX86 Series(RT-AX86U/RT-AX86S), RT-AX86U ZAKU II EDITION, RT-AX88U, RT-AX92U, TUF Gaming AX3000, TUF Gaming AX5400 (TUF-AX5400), ASUS ZenWiFi XD6, ASUS ZenWiFi AX (XT8) before 3.0.0.4.386.45898, and RT-AX68U before 3.0.0.4."
neutral
neutral
neutral
neutral
KEV inclusion
"CISA's Known Exploited Vulnerabilities (KEV) catalog is the authoritative list of security flaws that have been confirmed exploited in real-world attacks."
neutral
DOSSIER SOURCES
- Asus - Wikipedia · en.wikipedia.org
- Asustek Computer Inc, 2357:TAI profile - FT.com · markets.ft.com
- ASUS, asusproductguide.asus.com · asusproductguide.asus.com
- Asus CVEs and Security Vulnerabilities - OpenCVE · app.opencve.io
- ASUS Fixes Critical Router Flaw Allowing Command Execution in MITM Attacks · vpncentral.com
- CISA Flags Critical ASUS Live Update Flaw After Evidence of Active ... · csirt.ncc.gov.ng
Open questions: What specific measures are being taken to secure the ASUS Live Update process? · What is the extent of the impact from the ASUS Live Update compromise (CVE-2025-59374)? · What is ASUS's process for vulnerability disclosure and remediation?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-28 12:44:09.530140+00:00