ASUS has disclosed a critical authentication bypass vulnerability, tracked as CVE-2025-59367, affecting several of its DSL series router models, including DSL-AC51, DSL-N16, and DSL-AC750. This flaw allows remote, unauthenticated attackers to gain unauthorized access to unpatched devices exposed to the internet, with attacks requiring low complexity and no user interaction. ASUS has released firmware version 1.1.2.3_1010 to address the issue and strongly urges users to update their devices immediately. For users unable to update, ASUS recommends disabling all internet-accessible services such as remote WAN access, port forwarding, DDNS, VPN server, DMZ, port triggering, and FTP, as well as following best practices like using complex passwords and regularly checking for firmware updates.
The vulnerability has been assigned a critical CVSS score of 9.3, highlighting the significant risk it poses to affected devices. While there are currently no reports of active exploitation, the nature of the flaw makes it a prime target for attackers seeking to compromise routers for use in botnets or DDoS attacks. Users of end-of-life models that will not receive firmware updates are especially urged to implement the recommended mitigations to reduce their exposure to potential attacks.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
ASUS publicly warned users about the critical authentication bypass issue in its DSL series routers, drawing attention to the risk of remote compromise. Security reporting on November 14 amplified the vendor warning and the severity of the vulnerability.
A critical authentication bypass vulnerability, tracked as CVE-2025-59367, was publicly disclosed affecting ASUS DSL series routers. The flaw could allow remote attackers to gain unauthorized access to vulnerable devices.
3 references tracked. Mallory keeps watching after this page renders.
bleepingcomputer.com
Open sourcesecurityaffairs.com
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.