{"schema_version":1,"title":"ASUS vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 37 vulnerabilities in ASUS: 0 in the last 7 days and 27 in the last 90 days, 3 of them critical and 3 exploited in the wild. The most recent, CVE-2026-75811, was published on 8 September 2026. 5 technologies have a page of their own.","url":"https://junglewise.ai/threats/vendors/asus","json_url":"https://junglewise.ai/threats/vendors/asus.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/asus","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":1,"all_time":37,"critical":3,"exploited":3,"last_7_days":0,"last_30_days":12,"last_90_days":27,"last_365_days":34},"latest":[{"cve":"CVE-2026-75811","epss":0.0014,"slug":"cve-2026-75811-asus-armoury-crate-privilege-escalation-via-driver-authentication","title":"ASUS Armoury Crate privilege escalation via driver authentication bypass","severity":"info","exploited":false,"published_at":"2026-09-08T03:17:19.007+00:00","url":"https://junglewise.ai/threats/cve-2026-75811-asus-armoury-crate-privilege-escalation-via-driver-authentication"},{"cve":"CVE-2026-75810","epss":0.0015,"slug":"cve-2026-75810-asus-armoury-crate-exposed-dangerous-method-denial-of-service","title":"ASUS Armoury Crate exposed dangerous method denial of service","severity":"info","exploited":false,"published_at":"2026-09-08T03:17:18.88+00:00","url":"https://junglewise.ai/threats/cve-2026-75810-asus-armoury-crate-exposed-dangerous-method-denial-of-service"},{"cve":"CVE-2026-75809","epss":0.0015,"slug":"cve-2026-75809-asus-armoury-crate-privilege-escalation-via-insufficient-ioctl","title":"ASUS Armoury Crate privilege escalation via insufficient IOCTL access control","severity":"info","exploited":false,"published_at":"2026-09-08T03:17:18.763+00:00","url":"https://junglewise.ai/threats/cve-2026-75809-asus-armoury-crate-privilege-escalation-via-insufficient-ioctl"},{"cve":"CVE-2026-75808","epss":0.0015,"slug":"cve-2026-75808-asus-armoury-crate-resource-exhaustion-in-memory-allocation","title":"ASUS Armoury Crate resource exhaustion in memory allocation","severity":"info","exploited":false,"published_at":"2026-09-08T03:17:18.643+00:00","url":"https://junglewise.ai/threats/cve-2026-75808-asus-armoury-crate-resource-exhaustion-in-memory-allocation"},{"cve":"CVE-2026-19397","epss":0.002,"slug":"cve-2026-19397-asus-control-center-express-agent-missing-authentication-in","title":"ASUS Control Center Express Agent missing authentication in critical function","severity":"info","exploited":false,"published_at":"2026-09-08T03:17:18.507+00:00","url":"https://junglewise.ai/threats/cve-2026-19397-asus-control-center-express-agent-missing-authentication-in"},{"cve":"CVE-2026-18023","epss":0.0009,"slug":"cve-2026-18023-asus-armoury-crate-driver-sensitive-information-disclosure","title":"ASUS Armoury Crate driver sensitive information disclosure","severity":"info","exploited":false,"published_at":"2026-09-08T03:17:18.05+00:00","url":"https://junglewise.ai/threats/cve-2026-18023-asus-armoury-crate-driver-sensitive-information-disclosure"},{"cve":"CVE-2026-16006","epss":0.0009,"slug":"cve-2026-16006-asus-armoury-crate-kernel-virtual-address-disclosure-via-ioctl","title":"ASUS Armoury Crate kernel virtual address disclosure via IOCTL","severity":"info","exploited":false,"published_at":"2026-09-08T03:17:17.923+00:00","url":"https://junglewise.ai/threats/cve-2026-16006-asus-armoury-crate-kernel-virtual-address-disclosure-via-ioctl"},{"cve":"CVE-2026-16005","cvss":6.5,"epss":0.0009,"slug":"cve-2026-16005-asus-armoury-crate-driver-use-after-free-via-ioctl","title":"ASUS Armoury Crate driver use-after-free via IOCTL","severity":"info","exploited":false,"published_at":"2026-09-08T03:17:17.797+00:00","url":"https://junglewise.ai/threats/cve-2026-16005-asus-armoury-crate-driver-use-after-free-via-ioctl"},{"cve":"CVE-2026-16004","epss":0.0009,"slug":"cve-2026-16004-asus-armoury-crate-driver-insufficient-access-control-in-ioctl","title":"ASUS Armoury Crate driver insufficient access control in IOCTL","severity":"info","exploited":false,"published_at":"2026-09-08T03:17:17.68+00:00","url":"https://junglewise.ai/threats/cve-2026-16004-asus-armoury-crate-driver-insufficient-access-control-in-ioctl"},{"cve":"CVE-2026-16003","epss":0.0009,"slug":"cve-2026-16003-asus-armoury-crate-driver-privilege-escalation-via-ioctl-access","title":"ASUS Armoury Crate driver privilege escalation via IOCTL access control bypass","severity":"info","exploited":false,"published_at":"2026-09-08T03:17:17.55+00:00","url":"https://junglewise.ai/threats/cve-2026-16003-asus-armoury-crate-driver-privilege-escalation-via-ioctl-access"},{"cve":"CVE-2026-12962","epss":0.0036,"slug":"cve-2026-12962-asus-armoury-crate-cross-domain-policy-ntlm-hash-theft","title":"ASUS Armoury Crate cross-domain policy NTLM hash theft","severity":"info","exploited":false,"published_at":"2026-09-08T03:17:17.383+00:00","url":"https://junglewise.ai/threats/cve-2026-12962-asus-armoury-crate-cross-domain-policy-ntlm-hash-theft"},{"cve":"CVE-2026-75754","cvss":9.8,"epss":0.0034,"slug":"cve-2026-75754-asus-control-center-missing-authentication-and-hard-coded","title":"ASUS Control Center missing authentication and hard-coded credentials","severity":"info","exploited":false,"published_at":"2026-09-04T03:17:41.927+00:00","url":"https://junglewise.ai/threats/cve-2026-75754-asus-control-center-missing-authentication-and-hard-coded"},{"cve":"CVE-2026-19398","epss":0.0011,"slug":"cve-2026-19398-asus-fa507nu-and-fa507nv-bios-out-of-bounds-write-in-smiflash-smm","title":"ASUS FA507NU and FA507NV BIOS out-of-bounds write in SmiFlash SMM","severity":"info","exploited":false,"published_at":"2026-08-27T02:16:27.46+00:00","url":"https://junglewise.ai/threats/cve-2026-19398-asus-fa507nu-and-fa507nv-bios-out-of-bounds-write-in-smiflash-smm"},{"cve":"CVE-2026-8917","epss":0.0015,"slug":"cve-2026-8917-asus-gpu-tweak-untrusted-pointer-dereference-ioctl-privilege","title":"ASUS GPU Tweak untrusted pointer dereference IOCTL privilege escalation","severity":"info","exploited":false,"published_at":"2026-08-11T03:18:01.9+00:00","url":"https://junglewise.ai/threats/cve-2026-8917-asus-gpu-tweak-untrusted-pointer-dereference-ioctl-privilege"},{"cve":"CVE-2026-16727","cvss":7.3,"slug":"cve-2026-16727-asus-armoury-crate-race-condition-privilege-escalation","title":"ASUS Armoury Crate race condition privilege escalation","severity":"info","exploited":false,"published_at":"2026-07-30T02:16:45.537+00:00","url":"https://junglewise.ai/threats/cve-2026-16727-asus-armoury-crate-race-condition-privilege-escalation"},{"cve":"CVE-2019-25764","cvss":7.3,"slug":"cve-2019-25764-asus-aura-sync-privilege-escalation-in-driver-ioctl","title":"ASUS AURA SYNC privilege escalation in driver IOCTL","severity":"info","exploited":false,"published_at":"2026-07-17T07:16:37.193+00:00","url":"https://junglewise.ai/threats/cve-2019-25764-asus-aura-sync-privilege-escalation-in-driver-ioctl"},{"cve":"CVE-2026-8920","cvss":8.5,"slug":"cve-2026-8920-asus-aura-wallpaper-service-path-traversal-and-communication","title":"ASUS Aura Wallpaper Service path traversal and communication bypass","severity":"info","exploited":false,"published_at":"2026-07-15T02:22:57.79+00:00","url":"https://junglewise.ai/threats/cve-2026-8920-asus-aura-wallpaper-service-path-traversal-and-communication"},{"cve":"CVE-2026-8919","cvss":7.2,"slug":"cve-2026-8919-asus-gamesdk-permissive-cross-domain-policy-in-local-service","title":"ASUS GameSDK permissive cross-domain policy in local service endpoint","severity":"info","exploited":false,"published_at":"2026-07-15T02:22:57.653+00:00","url":"https://junglewise.ai/threats/cve-2026-8919-asus-gamesdk-permissive-cross-domain-policy-in-local-service"},{"cve":"CVE-2026-15030","cvss":5.6,"slug":"cve-2026-15030-asus-system-control-interface-out-of-bounds-read-via-ioctl","title":"ASUS System Control Interface out-of-bounds read via IOCTL","severity":"info","exploited":false,"published_at":"2026-07-15T02:18:13.173+00:00","url":"https://junglewise.ai/threats/cve-2026-15030-asus-system-control-interface-out-of-bounds-read-via-ioctl"},{"cve":"CVE-2026-15029","cvss":8.4,"slug":"cve-2026-15029-asus-system-control-interface-untrusted-pointer-dereference","title":"ASUS System Control Interface Untrusted Pointer Dereference","severity":"info","exploited":false,"published_at":"2026-07-15T02:18:13.033+00:00","url":"https://junglewise.ai/threats/cve-2026-15029-asus-system-control-interface-untrusted-pointer-dereference"},{"cve":"CVE-2026-13585","cvss":8.2,"slug":"cve-2026-13585-asus-system-control-interface-and-business-manager-information","title":"ASUS System Control Interface and Business Manager Information Disclosure and DoS","severity":"info","exploited":false,"published_at":"2026-07-15T02:18:12.213+00:00","url":"https://junglewise.ai/threats/cve-2026-13585-asus-system-control-interface-and-business-manager-information"},{"cve":"CVE-2026-13385","cvss":9.5,"slug":"cve-2026-13385-asus-router-remote-command-execution-via-improper-certificate","title":"ASUS Router remote command execution via improper certificate validation","severity":"info","exploited":false,"published_at":"2026-07-15T02:18:12.09+00:00","url":"https://junglewise.ai/threats/cve-2026-13385-asus-router-remote-command-execution-via-improper-certificate"},{"cve":"CVE-2026-11851","cvss":5.9,"slug":"cve-2026-11851-asus-router-sql-injection-in-web-management-interface","title":"ASUS Router SQL injection in web management interface","severity":"info","exploited":false,"published_at":"2026-07-15T02:18:04.743+00:00","url":"https://junglewise.ai/threats/cve-2026-11851-asus-router-sql-injection-in-web-management-interface"},{"cve":"CVE-2026-8921","cvss":8.5,"slug":"cve-2026-8921-asus-business-manager-privilege-escalation-via-tampered-ipc","title":"ASUS Business Manager privilege escalation via tampered IPC message","severity":"info","exploited":false,"published_at":"2026-07-03T03:16:23.627+00:00","url":"https://junglewise.ai/threats/cve-2026-8921-asus-business-manager-privilege-escalation-via-tampered-ipc"},{"cve":"CVE-2026-12960","cvss":6,"slug":"cve-2026-12960-asus-router-app-improper-export-of-android-components","title":"ASUS Router App improper export of Android components","severity":"info","exploited":false,"published_at":"2026-07-03T03:16:23.49+00:00","url":"https://junglewise.ai/threats/cve-2026-12960-asus-router-app-improper-export-of-android-components"}],"vendor":{"hub":true,"name":"ASUS","slug":"asus","homepage":"https://www.asus.com/","description":"A multinational computer hardware and consumer electronics company.","url":"https://junglewise.ai/threats/vendors/asus"},"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":4},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":8},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":11},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"most_severe":[{"cve":"CVE-2021-32030","cvss":9.8,"epss":0.9422,"slug":"cve-2021-32030-asus-routers-authentication-bypass-in-administrator-interface","title":"ASUS Routers authentication bypass in administrator interface","severity":"critical","exploited":true,"published_at":"2025-06-02T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2021-32030-asus-routers-authentication-bypass-in-administrator-interface"},{"cve":"CVE-2025-59374","cvss":9.8,"epss":0.012,"slug":"cve-2025-59374-asus-live-update-supply-chain-compromise-and-embedded-malicious","title":"\"UNSUPPORTED WHEN ASSIGNED\" Certain versions of the ASUS Live Update client were distributed with unauthorized modifications introduced thro","severity":"critical","exploited":true,"published_at":"2025-12-17T05:16:13.08+00:00","url":"https://junglewise.ai/threats/cve-2025-59374-asus-live-update-supply-chain-compromise-and-embedded-malicious"},{"cve":"CVE-2023-39780","cvss":8.8,"epss":0.4109,"slug":"cve-2023-39780-asus-rt-ax55-os-command-injection-in-start-apply-htm","title":"ASUS RT-AX55 OS command injection in start_apply.htm","severity":"critical","exploited":true,"published_at":"2025-06-02T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2023-39780-asus-rt-ax55-os-command-injection-in-start-apply-htm"},{"cve":"CVE-2025-15101","cvss":8.8,"slug":"cve-2025-15101-asus-router-firmware-os-command-injection-in-web-management","title":"ASUS Router Firmware OS command injection in web management interface","severity":"high","exploited":false,"published_at":"2026-03-26T03:16:02.4+00:00","url":"https://junglewise.ai/threats/cve-2025-15101-asus-router-firmware-os-command-injection-in-web-management"},{"cve":"CVE-2017-5632","cvss":6.5,"slug":"cve-2017-5632-asus-rt-n56u-denial-of-service-in-wan-connection","title":"ASUS RT-N56U denial of service in WAN connection","severity":"medium","exploited":false,"published_at":"2017-01-30T04:59:00.737+00:00","url":"https://junglewise.ai/threats/cve-2017-5632-asus-rt-n56u-denial-of-service-in-wan-connection"},{"cve":"CVE-2026-75754","cvss":9.8,"epss":0.0034,"slug":"cve-2026-75754-asus-control-center-missing-authentication-and-hard-coded","title":"ASUS Control Center missing authentication and hard-coded credentials","severity":"info","exploited":false,"published_at":"2026-09-04T03:17:41.927+00:00","url":"https://junglewise.ai/threats/cve-2026-75754-asus-control-center-missing-authentication-and-hard-coded"},{"cve":"CVE-2026-13385","cvss":9.5,"slug":"cve-2026-13385-asus-router-remote-command-execution-via-improper-certificate","title":"ASUS Router remote command execution via improper certificate validation","severity":"info","exploited":false,"published_at":"2026-07-15T02:18:12.09+00:00","url":"https://junglewise.ai/threats/cve-2026-13385-asus-router-remote-command-execution-via-improper-certificate"},{"cve":"CVE-2026-8920","cvss":8.5,"slug":"cve-2026-8920-asus-aura-wallpaper-service-path-traversal-and-communication","title":"ASUS Aura Wallpaper Service path traversal and communication bypass","severity":"info","exploited":false,"published_at":"2026-07-15T02:22:57.79+00:00","url":"https://junglewise.ai/threats/cve-2026-8920-asus-aura-wallpaper-service-path-traversal-and-communication"},{"cve":"CVE-2026-8921","cvss":8.5,"slug":"cve-2026-8921-asus-business-manager-privilege-escalation-via-tampered-ipc","title":"ASUS Business Manager privilege escalation via tampered IPC message","severity":"info","exploited":false,"published_at":"2026-07-03T03:16:23.627+00:00","url":"https://junglewise.ai/threats/cve-2026-8921-asus-business-manager-privilege-escalation-via-tampered-ipc"},{"cve":"CVE-2022-4989","cvss":8.5,"slug":"cve-2022-4989-asus-ai-suite-3-privilege-escalation-in-driver","title":"ASUS AI Suite 3 privilege escalation in driver","severity":"info","exploited":false,"published_at":"2026-07-03T03:16:22.1+00:00","url":"https://junglewise.ai/threats/cve-2022-4989-asus-ai-suite-3-privilege-escalation-in-driver"}],"generated_at":"2026-09-26T09:11:00.170868+00:00","technologies":[{"name":"ASUS Armoury Crate","slug":"armoury-crate","vulnerabilities":13,"url":"https://junglewise.ai/threats/technologies/armoury-crate"},{"name":"ASUS Business Manager","slug":"business-manager","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/business-manager"},{"name":"ASUS System Control Interface","slug":"system-control-interface","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/system-control-interface"},{"name":"ASUS AI Suite 3","slug":"ai-suite-3","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/ai-suite-3"},{"name":"ASUS System Control Interface v3","slug":"system-control-interface-v3","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/system-control-interface-v3"}]}