An authentication-bypass vulnerability exists in AiCloud. This vulnerability can be triggered by an unintended side effect of the Samba functionality, potentially leading to allow execution of specific functions without proper authorization.
Refer to the Security Update for ASUS Router Firmware section on the ASUS Security Advisory for more information.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.asus.com/content/security-advisory/ |
|
History
Tue, 25 Nov 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 25 Nov 2025 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An authentication-bypass vulnerability exists in AiCloud. This vulnerability can be triggered by an unintended side effect of the Samba functionality, potentially leading to allow execution of specific functions without proper authorization. Refer to the Security Update for ASUS Router Firmware section on the ASUS Security Advisory for more information. | |
| First Time appeared |
Asus
Asus router |
|
| Weaknesses | CWE-22 CWE-78 |
|
| CPEs | cpe:2.3:a:asus:router:3.0.0.4_386:*:*:*:*:*:*:* cpe:2.3:a:asus:router:3.0.0.4_388:*:*:*:*:*:*:* cpe:2.3:a:asus:router:3.0.0.6_102:*:*:*:*:*:*:* |
|
| Vendors & Products |
Asus
Asus router |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: ASUS
Published: 2025-11-25T07:27:02.626Z
Updated: 2025-11-26T04:55:22.973Z
Reserved: 2025-09-15T01:36:47.356Z
Link: CVE-2025-59366
Updated: 2025-11-25T20:19:31.420Z
Status : Awaiting Analysis
Published: 2025-11-25T08:15:52.287
Modified: 2025-11-25T22:16:16.690
Link: CVE-2025-59366
No data.