CVE-2025-11775: ASUS Armoury Crate

Medium severity, CVSS 4.8. EPSS: 0.1% chance of exploitation in the next 30 days.

An out-of-bounds read vulnerability has been identified in the asComSvc service. This vulnerability can be triggered by sending specially crafted requests, which may lead to a service crash or partial loss of functionality. This vulnerability only affects ASUS motherboard series products. Refer to the 'Security Update for Armoury Crate App' section on the ASUS Security Advisory for more information.

Affected products

  • ASUS Armoury Crate: up to and including v6.3.4

Published 2025-12-17. Last modified 2026-06-17.