Full Breakdown
ASUS Addresses Critical AiCloud Vulnerability in Router Firmware
11/28/2025, 3:52:26 AM
Overview of the Vulnerability
ASUS has released a critical firmware update to address a significant authentication-bypass vulnerability, tracked as CVE-2025-593656, affecting its AiCloud-enabled routers. This flaw, which has a severity score of 9.2 out of 10, allows unauthenticated remote code execution (RCE), posing a substantial risk to users. The vulnerability arises from issues within the Samba file-sharing code, enabling attackers to execute operating system commands without valid credentials.
Affected Devices and Recommendations
The vulnerability impacts various firmware versions, specifically 3.0.0.4_386, 3.0.0.4_388, and 3.0.0.6_102. Although ASUS has not provided a definitive list of affected router models, any AiCloud-enabled router running these firmware versions is potentially at risk. Users are strongly urged to update their firmware immediately or disable services such as AiCloud, Samba/file-sharing, and remote WAN access to mitigate the risk. Additionally, changing admin and Wi-Fi passwords to stronger alternatives is recommended.
Background and Context
This recent vulnerability is not an isolated incident; it follows a similar critical flaw addressed by ASUS in April 2025, which also affected AiCloud-enabled routers. The ongoing exploitation of vulnerabilities in ASUS routers has been highlighted by recent cybercriminal activities, including the WrtHug attacks, which have targeted outdated devices globally, particularly in regions like Taiwan, the United States, and Russia.
Official Statements & Responses
ASUS has emphasized the urgency of updating router firmware to protect devices from potential exploitation. The company stated, “To protect your devices, ASUS strongly recommends that all users update their router firmware to the latest version immediately.” This advisory reflects the company's commitment to user security amid rising cyber threats.
Criticism & Opposition
Despite the proactive measures taken by ASUS, critics have raised concerns regarding the security of end-of-life (EOL) devices. Many users may not be aware that their routers are no longer receiving updates, leaving them vulnerable to attacks. Security experts argue that manufacturers should provide clearer communication about the risks associated with EOL devices and offer more robust solutions for users who cannot upgrade their hardware.
Conflicting Reports & Gaps
While ASUS has patched multiple vulnerabilities in its routers, including CVE-2025-59366, reports indicate that various other vulnerabilities have been exploited in the past, such as OS command injection and arbitrary command execution. The exact number of devices affected and the extent of exploitation remain unclear, highlighting a gap in transparency regarding the security landscape of ASUS routers.
Verbatim Quotes
- “An authentication-bypass vulnerability exists in AiCloud. This vulnerability can be triggered by an unintended side effect of the Samba functionality, potentially leading to allow execution of specific functions without proper authorization.” — ASUS Security Advisory
- “To protect your devices, ASUS strongly recommends that all users update their router firmware to the latest version immediately.” — ASUS Security Advisory
- “Researchers have reported potential vulnerabilities in ASUS Router. ASUS has released mitigations for these vulnerabilities.” — ASUS Security Advisory
In summary, ASUS's recent firmware update addresses critical vulnerabilities in its AiCloud-enabled routers, underscoring the importance of timely updates and user awareness in maintaining cybersecurity.
