vciy

CVEs we hold for Asus

Records whose assigning authority named Asus as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-8921no title heldASUS Business Manager
CVE-2026-8920no title heldASUS Aura Wallpaper Service
CVE-2026-8919no title heldASUS GameSDK
CVE-2026-8918no title heldASUS Armoury Crate
CVE-2026-8917no title heldASUS VGAdll
CVE-2026-8070no title heldASUS Armoury Crate
CVE-2026-75811no title heldASUS Armoury Crate
CVE-2026-75810no title heldASUS Armoury Crate
CVE-2026-75809no title heldASUS Armoury Crate
CVE-2026-75808no title heldASUS Armoury Crate
CVE-2026-75754no title heldASUS Control Center Enterprise (ACC)
CVE-2026-7480no title heldASUS System Control Interface
CVE-2026-6737no title heldASUS AsusPTPFilter
CVE-2026-67248A stack-based buffer overflow vulnerability was found in the File Explorer on the ADMASUSTOR Inc. ADM
CVE-2026-67247A path traversal vulnerability was found in the IHM Log handling of ADMASUSTOR Inc. ADM
CVE-2026-67246A path traversal vulnerability was found in the Wallpaper component of ADMASUSTOR Inc. ADM
CVE-2026-67245A path traversal vulnerability was found in the VPN Clients on the ADMASUSTOR Inc. ADM
CVE-2026-67244A format string vulnerability was found in the Notification OAuth settings of ADMASUSTOR Inc. ADM
CVE-2026-6644A command injection vulnerability was found in the PPTP VPN Clients on the ADMASUSTOR Inc. ADM
CVE-2026-6643A stack-based buffer overflow vulnerability in the VPN Clients on the ADMASUSTOR Inc. ADM
CVE-2026-3508no title heldASUS System Control Interface
CVE-2026-3428no title heldASUS Member Center(华硕大厅)
CVE-2026-3179A path traversal vulnerability was found in the FTP Backup on the ADM.ASUSTOR ADM
CVE-2026-3100An improper certificate validation vulnerability was found in the FTP Backup on the ADM.ASUSTOR ADM
CVE-2026-24936An improper input validation vulnerability was found in ADM while joining a AD Domain.ASUSTOR ADM
CVE-2026-24935An improper certificate validation vulnerability was found in a third-party NAT traversal module.ASUSTOR ADM
CVE-2026-24934An improper certificate validation vulnerability was found in ADM while querying an external server for the device's…ASUSTOR ADM
CVE-2026-24933An improper certificate validation vulnerability was found in ADM while sending HTTPS requests to the server.ASUSTOR ADM
CVE-2026-24932An improper certificate validation vulnerability was found in ADM while updating the DDNS settings.ASUSTOR ADM
CVE-2026-19398no title heldASUS FA507NU
CVE-2026-19397no title heldASUS Control Center Express Agent
CVE-2026-1880no title heldASUS DriverHub
CVE-2026-1878no title heldASUS Driver( Headset )
CVE-2026-18759An improper authentication and path traversal vulnerability exists in ASUSTOR Backup Plan and ASUSTOR EZ Sync.ASUSTOR Inc. AES
CVE-2026-18188A format string vulnerability was found in the Rsync Backup on the ADMASUSTOR Inc. ADM
CVE-2026-18187A format string vulnerability was found in the Internal Backup on the ADMASUSTOR Inc. ADM
CVE-2026-18186A stored format string vulnerability was found in the FTP Backup on the ADMASUSTOR Inc. ADM
CVE-2026-18023no title heldASUS Armoury Crate
CVE-2026-16727no title heldASUS Armoury Crate
CVE-2026-16006no title heldASUS Armoury Crate
CVE-2026-16005no title heldASUS Armoury Crate
CVE-2026-16004no title heldASUS Armoury Crate
CVE-2026-16003no title heldASUS Armoury Crate
CVE-2026-15030no title heldASUS Business Manager
CVE-2026-15029no title heldASUS Business Manager
CVE-2026-13585no title heldASUS Business Manager
CVE-2026-13385no title heldASUS Router
CVE-2026-12962no title heldASUS Armoury Crate
CVE-2026-12960no title heldASUS Router app
CVE-2026-11851no title heldASUS Router
CVE-2025-9968no title heldASUS Armoury Crate
CVE-2025-9338no title heldASUS Armoury Crate
CVE-2025-9337no title heldASUS Armoury Crate
CVE-2025-9336no title heldASUS Armoury Crate
CVE-2025-8070Windows service registered with an unquoted ImagePath vulnerability in the system registryASUSTOR ABP and AES
CVE-2025-7699An improper access control vulnerability was found in the EZ Sync Manager of ADMASUSTOR ADM
CVE-2025-7618A stored Cross-Site Scripting (XSS) vulnerability exists in the File Explorer and Text Editor of ADMASUSTOR ADM
CVE-2025-7380A stored Cross-Site Scripting (XSS) vulnerability exists in the Access Control of ADMASUSTOR ADM
CVE-2025-7379A security bypass vulnerability was found in DataSync Center installed on ADMASUSTOR ADM
CVE-2025-7378An improper input validation vulnerability was found on manipulating configuration of ADMASUSTOR ADM
CVE-2025-6398no title heldASUS AI Suite
CVE-2025-59374no title heldASUS live update
CVE-2025-59373no title heldASUS MyASUS
CVE-2025-59372no title heldASUS Router
CVE-2025-59371no title heldASUS Router
CVE-2025-59370no title heldASUS Router
CVE-2025-59369no title heldASUS Router
CVE-2025-59368no title heldASUS Router
CVE-2025-59367no title heldASUS DSL-AC750
CVE-2025-59366no title heldASUS Router
CVE-2025-59365no title heldASUS Router
CVE-2025-4570no title heldASUS MyASUS
CVE-2025-4569no title heldASUS MyASUS
CVE-2025-3464no title heldASUS Armoury Crate
CVE-2025-3463no title heldASUS DriverHub
CVE-2025-3462no title heldASUS DriverHub
CVE-2025-2492no title heldASUS Router
CVE-2025-2027no title heldASUS ASCI
CVE-2025-1533no title heldASUS Armoury Crate
CVE-2025-15101no title heldASUS Router
CVE-2025-15038no title heldASUS Business System Control Interface
CVE-2025-15037no title heldASUS Business System Control Interface
CVE-2025-1354no title heldASUS RT-N10E
CVE-2025-13348no title heldASUS Business Manager
CVE-2025-13053A missing encryption of sensitive data vulnerability was found in the UPS settings of ADMASUSTOR ADM
CVE-2025-13052An improper certificates validation vulnerability was found in the Notification settings of ADMASUSTOR ADM
CVE-2025-13051Windows service used an uncontrolled search path element will cause unauthorized code execution with localsystem…ASUSTOR ABP and AES
CVE-2025-12793no title heldASUS ASCI
CVE-2025-12003no title heldASUS Router
CVE-2025-11901no title heldASUS Z790 series
CVE-2025-11775no title heldASUS Armoury Crate
CVE-2024-55408no title heldASUS ASCI
CVE-2024-3912ASUS Router - Upload arbitrary firmwareASUS DSL-AC55
CVE-2024-31163ASUS Download Master - Buffer OverflowASUS Download Master
CVE-2024-31162ASUS Download Master - OS Command InjectionASUS Download Master
CVE-2024-31161ASUS Download Master - Arbitrary File UploadASUS Download Master
CVE-2024-31160ASUS Download Master - Stored XSSASUS Download Master
CVE-2024-31159ASUS Download Master - Reflected XSSASUS Download Master
CVE-2024-3080ASUS Router - Improper AuthenticationASUS RT-AC68U
CVE-2024-3079ASUS Router - Stack-based Buffer OverflowASUS RT-AC68U
CVE-2024-1655ASUS WiFi Router - OS Command InjectionASUS RT-AX57 Go
CVE-2024-13062no title heldASUS Router
CVE-2024-12957no title heldASUS Armoury Crate
CVE-2024-12912no title heldASUS Router
CVE-2024-11985no title heldASUS RT-AX58U V2
CVE-2024-0401ASUS OVPN RCEASUS RT-AX3000
CVE-2023-5716ASUS Armoury Crate - Arbitrary File WriteASUS Armoury Crate
CVE-2023-47678no title heldASUSTeK COMPUTER INC. RT-AC87U
CVE-2023-4475An Arbitrary File Movement vulnerability was found on the ADMASUSTOR ADM
CVE-2023-41349ASUS RT-AX88U - externally-controlled format stringASUS RT-AX88U
CVE-2023-41348ASUS RT-AX55 - command injection - 4ASUS RT-AX55
CVE-2023-41347ASUS RT-AX55 - command injection - 3ASUS RT-AX55
CVE-2023-41346ASUS RT-AX55 - command injection - 2ASUS RT-AX55
CVE-2023-41345ASUS RT-AX55 - command injection - 1ASUS RT-AX55
CVE-2023-39780no title heldASUS RT-AX55
CVE-2023-39240ASUS RT-AX55、RT-AX56U_V2 - Format String - 3ASUS RT-AX56U_V2
CVE-2023-39239ASUS RT-AX55、RT-AX56U_V2、RT-AC86U - Format String - 2ASUS RT-AC86U
CVE-2023-39238ASUS RT-AX55、RT-AX56U_V2 - Format String - 1ASUS RT-AX56U_V2
CVE-2023-39237ASUS RT-AC86U - Command injection vulnerability - 5ASUS RT-AC86U
CVE-2023-39236ASUS RT-AC86U - Command injection vulnerability - 4ASUS RT-AC86U
CVE-2023-38033ASUS RT-AC86U - Command injection vulnerability - 3ASUS RT-AC86U
CVE-2023-38032ASUS RT-AC86U - Command injection vulnerability - 2ASUS RT-AC86U
CVE-2023-38031ASUS RT-AC86U - Command injection vulnerability - 1ASUS RT-AC86U
CVE-2023-3699An Improper Privilege Management vulnerability was found on the ADMASUSTOR ADM
CVE-2023-3698A Command injection vulnerability was found on Printer service of ADMASUSTOR ADM
CVE-2023-3697A Command injection vulnerability was found on Printer service of ADMASUSTOR ADM
CVE-2023-35720ASUS RT-AX92U lighttpd mod_webdav.so SQL Injection Information Disclosure VulnerabilityASUS RT-AX92U
CVE-2023-35087ASUS RT-AX56U V2 & RT-AC86U - Format String - 2ASUS RT-AC86U
CVE-2023-35086ASUS RT-AX56U V2 & RT-AC86U - Format String -1ASUS RT-AC86U
CVE-2023-34360ASUS RT-AX88U - Stored XSSASUS RT-AX88U
CVE-2023-34359ASUS RT-AX88U - Out-of-bounds Read - 2ASUS RT-AX88U
CVE-2023-34358ASUS RT-AX88U - Out-of-bounds Read - 1ASUS RT-AX88U
CVE-2023-31195no title heldASUSTeK COMPUTER INC. ASUS Router RT-AX3000
CVE-2023-30770A stack-based buffer overflow vulnerability was found in the ADMASUSTOR ADM
CVE-2023-2910A Command injection vulnerability was found on Printer service of ADMASUSTOR ADM
CVE-2023-2909A Directory traversal vulnerability was found on EZ Sync service of ADMASUSTOR ADM
CVE-2023-28703ASUS RT-AC86U - Buffer OverflowASUS RT-AC86U
CVE-2023-28702ASUS RT-AC86U - Command InjectionASUS RT-AC86U
CVE-2023-2749A Gain Information vulnerability was found on Download Center.ASUSTOR Download Center
CVE-2023-2509A Cross-Site Scripting(XSS) vulnerability was found on ADMASUSTOR SoundsGood
CVE-2022-4990no title heldASUS AI Suite 3
CVE-2022-4989no title heldASUS AI Suite 3
CVE-2022-4221OS command injection in ASUS M25 NASAsus NAS-M25
CVE-2022-38699ASUS Armoury Crate Service - Arbitrary File Creation via Elevation of Privilege FlawASUS Armoury Crate Service
CVE-2022-38393no title heldAsus RT-AX82U
CVE-2022-38105no title heldAsus RT-AX82U
CVE-2022-37398A stack-based buffer overflow vulnerability was found on ADMASUSTOR ADM
CVE-2022-35401no title heldAsus RT-AX82U
CVE-2022-26674ASUS RT-AX88U - Format StringASUS RT-AX88U
CVE-2022-26673ASUS RT-AX88U - Stored XSSASUS RT-AX88U
CVE-2022-26672ASUS WebStorage - Use of Hard-coded CredentialsASUS WebStorage
CVE-2022-26669ASUS Control Center - SQL InjectionASUS Control Center
CVE-2022-26668ASUS Control Center - Broken Access ControlASUS Control Center
CVE-2022-26376no title heldAsuswrt-Merlin New Gen
CVE-2022-25597ASUS RT-AC86U - Command InjectionASUS RT-AC86U
CVE-2022-25596ASUS RT-AC86U - Heap-based buffer overflowASUS RT-AC86U
CVE-2022-25595ASUS RT-AC86U - Improper Input ValidationASUS RT-AC86U
CVE-2022-23973ASUS RT-AX56U - Stack overflewASUS RT-AX56U
CVE-2022-23972ASUS RT-AX56U - SQL InjectionASUS RT-AX56U
CVE-2022-23971ASUS RT-AX56U - Path TraversalASUS RT-AX56U
CVE-2022-23970ASUS RT-AX56U - Path TraversalASUS RT-AX56U
CVE-2022-22262ASUS Armoury Crate & Aura Creator Installer之ROG Live Service - Improper Link Resolution Before File AccessASUS Armoury Crate & Aura Creator Installer (ROG Live…
CVE-2022-22054ASUS RT-AX56U - Path TraversalASUS RT-AX56U
CVE-2022-21933ASUS VivoMini/Mini PC - improper input validationASUS UN65U
CVE-2021-44158ASUS RT-AX56U Router - Stack-based buffer overflowASUS RT-AX56U
CVE-2021-41289ASUS P453UJ - Improper Restriction of Operations within the Bounds of a Memory BufferASUS P453UJ BIOS
CVE-2021-37910ASUS GT-AXE11000, RT-AX3000, RT-AX55, RT-AX58U, TUF-AX3000 - Improper AuthenticationASUS TUF-AX3000
CVE-2021-28209ASUS BMC's firmware: path traversal - Delete video file functionASUS BMC firmware for Z11PR-D16
CVE-2021-28208ASUS BMC's firmware: path traversal - Get video file functionASUS BMC firmware for Z11PR-D16
CVE-2021-28207ASUS BMC's firmware: path traversal - Get Help file functionASUS BMC firmware for Z11PR-D16
CVE-2021-28206ASUS BMC's firmware: path traversal - Record video file functionASUS BMC firmware for Z11PR-D16
CVE-2021-28205ASUS BMC's firmware: path traversal - Delete SOL video file functionASUS BMC firmware for Z10PE-D16 WS
CVE-2021-28204ASUS BMC's firmware: command injection - Modify user’s information functionASUS BMC firmware for Z10PE-D16 WS
CVE-2021-28203ASUS BMC's firmware: command injection - Web Set Media Image functionASUS BMC firmware for Z10PE-D16 WS
CVE-2021-28202ASUS BMC's firmware: buffer overflow - Service configuration-2 functionASUS BMC firmware for Z11PR-D16
CVE-2021-28201ASUS BMC's firmware: buffer overflow - Service configuration-1 functionASUS BMC firmware for Z11PR-D16
CVE-2021-28200ASUS BMC's firmware: buffer overflow - CD media configuration functionASUS BMC firmware for Z11PR-D16
CVE-2021-28199ASUS BMC's firmware: buffer overflow - Modify user’s information functionASUS BMC firmware for Z11PR-D16
CVE-2021-28198ASUS BMC's firmware: buffer overflow - Firmware protocol configurationASUS BMC firmware for Z11PR-D16
CVE-2021-28197ASUS BMC's firmware: buffer overflow - Active Directory configuration functionASUS BMC firmware for Z11PR-D16
CVE-2021-28196ASUS BMC's firmware: buffer overflow - Generate SSL certificate functionASUS BMC firmware for Z11PR-D16
CVE-2021-28195ASUS BMC's firmware: buffer overflow - Radius configuration functionASUS BMC firmware for Z11PR-D16
CVE-2021-28194ASUS BMC's firmware: buffer overflow - Remote image configuration settingASUS BMC firmware for Z11PR-D16
CVE-2021-28193ASUS BMC's firmware: buffer overflow - SMTP configuration functionASUS BMC firmware for Z11PR-D16
CVE-2021-28192ASUS BMC's firmware: buffer overflow - Remote video storage functionASUS BMC firmware for Z11PR-D16
CVE-2021-28191ASUS BMC's firmware: buffer overflow - Firmware update functionASUS BMC firmware for Z11PR-D16
CVE-2021-28190ASUS BMC's firmware: buffer overflow - Generate new certificate functionASUS BMC firmware for Z11PR-D16
CVE-2021-28189ASUS BMC's firmware: buffer overflow - SMTP configuration functionASUS BMC firmware for Z10PE-D16 WS
CVE-2021-28188ASUS BMC's firmware: buffer overflow - Modify user’s information functionASUS BMC firmware for Z10PE-D16 WS
CVE-2021-28187ASUS BMC's firmware: buffer overflow - Generate new SSL certificateASUS BMC firmware for Z10PE-D16 WS
CVE-2021-28186ASUS BMC's firmware: buffer overflow - ActiveX configuration-2 acquisitionASUS BMC firmware for Z10PE-D16 WS
CVE-2021-28185ASUS BMC's firmware: buffer overflow - ActiveX configuration-1 acquisitionASUS BMC firmware for Z10PE-D16 WS
CVE-2021-28184ASUS BMC's firmware: buffer overflow - Active Directory configuration functionASUS BMC firmware for Z10PE-D16 WS
CVE-2021-28183ASUS BMC's firmware: buffer overflow - Web License configuration settingASUS BMC firmware for Z10PE-D16 WS
CVE-2021-28182ASUS BMC's firmware: buffer overflow - Web Service configuration functionASUS BMC firmware for Z10PE-D16 WS
CVE-2021-28181ASUS BMC's firmware: buffer overflow - Remote video configuration settingASUS BMC firmware for Z10PE-D16 WS
CVE-2021-28180ASUS BMC's firmware: buffer overflow - Audit log configuration settingASUS BMC firmware for Z10PE-D16 WS
CVE-2021-28179ASUS BMC's firmware: buffer overflow - Media support configuration settingASUS BMC firmware for Z10PE-D16 WS
CVE-2021-28178ASUS BMC's firmware: buffer overflow - UEFI configuration functionASUS BMC firmware for Z10PE-D16 WS
CVE-2021-28177ASUS BMC's firmware: buffer overflow - LDAP configuration functionASUS BMC firmware for Z10PE-D16 WS

200 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.