CVE-2024-1655: ASUS Expertwifi EBM63

High severity, CVSS 8.8. EPSS: 2% chance of exploitation in the next 30 days.

Certain ASUS WiFi routers models has an OS Command Injection vulnerability, allowing an authenticated remote attacker to execute arbitrary system commands by sending a specially crafted request.

Affected products

  • ASUS Expertwifi EBM63: before 3.0.0.6.102_32645 (fixed in 3.0.0.6.102_32645)
  • ASUS Expertwifi EBM68: before 3.0.0.6.102_44384 (fixed in 3.0.0.6.102_44384)
  • ASUS Rt-AX57 Go: before 3.0.0.6.102_22188 (fixed in 3.0.0.6.102_22188)

Published 2024-04-15. Last modified 2026-06-17.