A path traversal vulnerability has been identified in certain router models. A remote, authenticated attacker could exploit this vulnerability to write files outside the intended directory, potentially affecting device integrity.
Refer to the 'Security Update for ASUS Router Firmware' section on the ASUS Security Advisory for more information.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.asus.com/security-advisory/ |
|
History
Tue, 25 Nov 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 25 Nov 2025 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A path traversal vulnerability has been identified in certain router models. A remote, authenticated attacker could exploit this vulnerability to write files outside the intended directory, potentially affecting device integrity. Refer to the 'Security Update for ASUS Router Firmware' section on the ASUS Security Advisory for more information. | |
| First Time appeared |
Asus
Asus router |
|
| Weaknesses | CWE-22 | |
| CPEs | cpe:2.3:a:asus:router:3.0.0.4_386:*:*:*:*:*:*:* cpe:2.3:a:asus:router:3.0.0.4_388:*:*:*:*:*:*:* cpe:2.3:a:asus:router:3.0.0.6_102:*:*:*:*:*:*:* |
|
| Vendors & Products |
Asus
Asus router |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: ASUS
Published: 2025-11-25T07:30:54.219Z
Updated: 2025-11-25T14:04:34.837Z
Reserved: 2025-09-15T01:36:47.358Z
Link: CVE-2025-59372
Updated: 2025-11-25T14:03:33.673Z
Status : Awaiting Analysis
Published: 2025-11-25T08:15:53.180
Modified: 2025-11-25T22:16:16.690
Link: CVE-2025-59372
No data.