• News/
  • https://www.bleepingcomputer.com/news/security/asus-warns-of-critical-auth-bypass-flaw-in-routers-using-aicloud/

ASUS warns of critical auth bypass flaw in routers using AiCloud

BleepingComputer
·
Bill Toulas
·
Published Apr 18, 2025
·
Updated

ASUS is warning about an authentication bypass vulnerability in routers with AiCloud enabled that could allow remote attackers to perform unauthorized execution of functions on the device. The vulnerability, tracked under CVE-2025-2492 and rated critical (CVSS v4 score: 9.2), is remotely exploitable via a specially crafted request and requires no authentication, making it particularly dangerous. "An improper authentication control vulnerability exists in certain ASUS router firmware series," reads the vendor's bulletin. "This vulnerability can be triggered by a crafted request, potentially leading to unauthorized execution of functions." AiCloud is a cloud-based remote access feature built into many ASUS routers, turning them into mini private cloud servers. It allows users to access files stored on USB drives connected to the router from anywhere over the internet, stream media remotely, sync files between home networks and other cloud storage services, and share files with others via links. The vulnerability discovered in AiCloud impacts a broad range of models, with ASUS releasing fixes for multiple firmware branches, including 3.0.0.4_382 series, 3.0.0.4_386 series, 3.0.0.4_388 series, and 3.0.0.6_102 series. Users are recommended to upgrade to the latest firmware version available for their model, which they can find on the vendor's support portal or the product finder page. Detailed instructions on how to apply firmware updates are available here. ASUS also advises use...

Read full article

Affected Software

5 affected components
ASUS Router Firmware=3.0.0.4_382
ASUS Router Firmware=3.0.0.4_386
ASUS Router Firmware=3.0.0.4_388
ASUS Router Firmware=3.0.0.6_102
ASUS router

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a critical authentication bypass vulnerability in ASUS routers using AiCloud.

2

What security implications are discussed?

The vulnerability could allow remote attackers to execute unauthorized functions on affected routers.

3

What products or software are affected?

Affected products include specific versions of ASUS Router Firmware, namely versions 3.0.0.4_382, 3.0.0.4_386, 3.0.0.4_388, and 3.0.0.6_102.

4

How can users protect themselves against this vulnerability?

Users should ensure their router firmware is updated to the latest version provided by ASUS.

5

What is the CVE identifier for this vulnerability?

The vulnerability is tracked under CVE-2025-249.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203