Authentication Bypass Vulnerability in AiCloud by ASUS
CVE-2025-59366
9.2CRITICAL
What is CVE-2025-59366?
The AiCloud product by ASUS is prone to an authentication-bypass vulnerability arising from an unintended side effect in its Samba functionality. This flaw may enable unauthorized users to execute certain functions without proper authorization, potentially compromising the integrity and security of affected systems. Users are advised to refer to ASUS's security advisory for further details and recommended mitigation measures.
Affected Version(s)
Router 3.0.0.4_386
Router 3.0.0.4_388
Router 3.0.0.6_102
References
CVSS V4
Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Nanyu Zhong of VARAS@IIE