CVE-2025-2492: ASUS Router

Critical severity, CVSS 9.2. EPSS: 1.1% chance of exploitation in the next 30 days.

An improper authentication control vulnerability exists in AiCloud. This vulnerability can be triggered by a crafted request, potentially leading to unauthorized execution of functions. Refer to the 'ASUS Router AiCloud vulnerability' section on the ASUS Security Advisory for more information.

Affected products

  • ASUS Router: version 3.0.0.4_382 series only; version 3.0.0.4_386 series only; version 3.0.0.4_388 series only; version 3.0.0.6_102 series only

Published 2025-04-18. Last modified 2026-06-17.