ASUS is warning about an authentication bypass vulnerability in routers with AiCloud enabled that could allow remote attackers to perform unauthorized execution of functions on the device. The vulnerability, tracked under CVE-2025-2492 and rated critical (CVSS v4 score: 9.2), is remotely exploitable via a specially crafted request and requires no authentication, making it particularly dangerous. "An improper authentication control vulnerability exists in certain ASUS router firmware series," reads the vendor's bulletin. "This vulnerability can be triggered by a crafted request, potentially leading to unauthorized execution of functions." AiCloud is a cloud-based remote access feature built into many ASUS routers, turning them into mini private cloud servers. It allows users to access files stored on USB drives connected to the router from anywhere over the internet, stream media remotely, sync files between home networks and other cloud storage services, and share files with others via links. The vulnerability discovered in AiCloud impacts a broad range of models, with ASUS releasing fixes for multiple firmware branches, including 3.0.0.4_382 series, 3.0.0.4_386 series, 3.0.0.4_388 series, and 3.0.0.6_102 series. Users are recommended to upgrade to the latest firmware version available for their model, which they can find on the vendor's support portal or the product finder page. Detailed instructions on how to apply firmware updates are available here. ASUS also advises use...
ASUS warns of critical auth bypass flaw in routers using AiCloud
BleepingComputer
·Bill Toulas
·Published Apr 18, 2025
·Updated
Affected Software
5 affected components
ASUS Router Firmware=3.0.0.4_382
ASUS Router Firmware=3.0.0.4_386
ASUS Router Firmware=3.0.0.4_388
ASUS Router Firmware=3.0.0.6_102
ASUS router
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a critical authentication bypass vulnerability in ASUS routers using AiCloud.
2
What security implications are discussed?
The vulnerability could allow remote attackers to execute unauthorized functions on affected routers.
3
What products or software are affected?
Affected products include specific versions of ASUS Router Firmware, namely versions 3.0.0.4_382, 3.0.0.4_386, 3.0.0.4_388, and 3.0.0.6_102.
4
How can users protect themselves against this vulnerability?
Users should ensure their router firmware is updated to the latest version provided by ASUS.
5
What is the CVE identifier for this vulnerability?
The vulnerability is tracked under CVE-2025-249.