ASUS has urged users to apply security updates to its laptops, PCs and routers, as the hardware giant once again has to deal with multiple vulnerabilities in its products. Hot on the heels of Operation WrtHug, described as โa massive, coordinated effort that has compromised thousands of ASUS routers worldwide,โ comes the news of yet more vulnerabilities. One of which has a severity rating of 9.4 on the Common Vulnerability Scoring System (CVSS).
The vulnerabilities cover router hardware and computer software. All the vulnerabilities, including those covered by Operation WrtHug, have now been patched, with ASUS confirming the latest updates in security advisories released this week.
The first advisory concerns firmware across a number of ASUS routers. See below for the full list:
List of firmware used by ASUS routers that need to be patched
All the above firmware series are susceptible to multiple vulnerabilities. The most critical, that with the CVSS 9.4 rating, is CVE-2025-59366, an authentication bypass vulnerability in AiCloud that could lead to the โexecution of specific functions without proper authorisation”.
If that sounds bad, itโs because it is. Very bad indeed. โASUS strongly recommends that all users update their router firmware to the latest version immediately,โ the advisory warned.
Which is easier said than done when your router has reached end-of-life, of course, as these are unsupported and therefore aren’t given firmware updates. ASUS suggests that in this case users should โensure that both your router login and WiFi passwords are strong and unique,โ while at the same time disabling any services that are accessible from the internet.
Great advice there. Not! How about just buying a new router instead, if you want to still be able to actually use it?
MyASUS software vulnerability
The second advisory is a software one, but nonetheless important as the software concerned is MyASUS. Yes, the very same one that’s preinstalled on your ASUS computer to provide access to support tools and, the irony, system updates.
The vulnerability in question impacts the System Control Interface Service of MyASUS, and could enable an attacker with low privileges to escalate these and execute arbitrary files as SYSTEM.
ASUS has confirmed that the vulnerability and the security update apply to โall personal computers, including desktop, laptop, NUC, and All-in-One PCโ.
It goes without saying, but here I am saying it anyway, you should go visit the Asus support site and download the necessary security updates as a matter of some urgency.
With four decades of experience, Davey is one of the UK's most respected cybersecurity writers and a contributing editor to PC Pro magazine. He is also a senior contributor at Forbes. You can find him at TechFinitive covering all things cybersecurity.
To provide the best experiences, we and our partners use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us and our partners to process personal data such as browsing behavior or unique IDs on this site and show (non-) personalized ads. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Click below to consent to the above or make granular choices. Your choices will be applied to this site only. You can change your settings at any time, including withdrawing your consent, by using the toggles on the Cookie Policy, or by clicking on the manage consent button at the bottom of the screen.
Functional
Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes.The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional
Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes.The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.