Insecure Key Storage in MyASUS Software by ASUS
CVE-2025-4570

6.9MEDIUM

Key Information:

Vendor

Asus

Status
Vendor
CVE Published:
21 July 2025

What is CVE-2025-4570?

A vulnerability has been identified in the MyASUS software, where sensitive key management is implemented insecurely. This issue could allow unauthorized individuals to gain access to critical tokens, which could then be exploited to communicate with specific services without proper authorization. It is essential for users of MyASUS to be aware of this flaw and take appropriate actions to safeguard their data.

Affected Version(s)

MyASUS 4.0.35.0 and earlier

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-4570 : Insecure Key Storage in MyASUS Software by ASUS