CVE-2025-13348: ASUS Business Manager

High severity, CVSS 8.5. EPSS: 0.1% chance of exploitation in the next 30 days.

An improper access control vulnerability exists in ASUS Secure Delete Driver of ASUS Business Manager. This vulnerability can be triggered by a local user sending a specially crafted request, potentially leading to the creation of arbitrary files in a specified path. Refer to the "Security Update for ASUS Business Manager" section on the ASUS Security Advisory for more information.

Affected products

  • ASUS ASUS Business Manager: before 3.0.37.0 (fixed in 3.0.37.0)

Published 2026-02-02. Last modified 2026-06-17.